๐ง๐ช
madeit
2026-08-29 21:05:48
(18 hours ago)
Web App Attack
๐ง๐ช
madeit
2026-08-06 05:04:55
(3 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 11:08:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 07:08:08.846870 2026] [security2:error] [pid 17974:tid 18043] [client 162.158.63.28:14289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.asetiadi.net"] [uri "/.env"] [unique_id "ajUjGKRNopppKH5XmnfiEgAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-16 22:02:54
(2 months ago)
Auto-ban: >3000 req/min op 2026-06-16
Web App Attack
SSH
Hacking
๐ง๐ฌ
Stoyko Stoykov
2026-06-13 14:22:49
(2 months ago)
162.158.63.28 - - [13/Jun/2026:17:22:49 +0300] "GET /.git/config HTTP/2.0" 404 134 "-" "Mozilla/5.0 ...
show more
162.158.63.28 - - [13/Jun/2026:17:22:49 +0300] "GET /.git/config HTTP/2.0" 404 134 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15.7; rv:149.0) Gecko/20100101 Firefox/149.0"
...
show less
Hacking
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-05-28 01:02:59
(3 months ago)
162.158.63.28 - - [28/May/2026:04:02:58 +0300] "GET /api/.env HTTP/2.0" 404 134 "-" "Mozilla/5.0 (Ma ...
show more
162.158.63.28 - - [28/May/2026:04:02:58 +0300] "GET /api/.env HTTP/2.0" 404 134 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_7_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Safari/605.1.15"
...
show less
Hacking
Web App Attack
๐ต๐ฑ
IROK
2026-03-31 04:05:47
(4 months ago)
Malware/WebShell Scan blocked by ModSecurity
...
Hacking
Anonymous
2026-03-25 19:45:07
(5 months ago)
[Wed Mar 25 20:45:06.980731 2026] [authz_core:error] [pid 23225] [client 162.158.63.28:11481] AH0163 ...
show more
[Wed Mar 25 20:45:06.980731 2026] [authz_core:error] [pid 23225] [client 162.158.63.28:11481] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Mar 25 20:45:07.171842 2026] [authz_core:error] [pid 23225] [client 162.158.63.28:11481] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Mar 25 20:45:07.404043 2026] [authz_core:error] [pid 23225] [client 162.158.63.28:11481] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-03-23 16:15:43
(5 months ago)
162.158.63.28 - - [23/Mar/2026:18:15:40 +0200] "GET /wp-includes/ HTTP/1.1" 404 351 "-" "Mozilla/5.0 ...
show more
162.158.63.28 - - [23/Mar/2026:18:15:40 +0200] "GET /wp-includes/ HTTP/1.1" 404 351 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.158.63.28 - - [23/Mar/2026:18:15:42 +0200] "GET /cgi-bin/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
LotPhantom
2026-03-20 16:43:00
(5 months ago)
2026/03/20 16:42:59 [error] 2491775#2491775: *167711 access forbidden by rule, client: 162.158.63.28 ...
show more
2026/03/20 16:42:59 [error] 2491775#2491775: *167711 access forbidden by rule, client: 162.158.63.28, server: wynnesmiles.bridginggaps.tech, request: "GET /.git/refs/heads/main HTTP/2.0", host: "wynnesmiles.bridginggaps.tech"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:47:19
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:47:11.064483 2026] [security2:error] [pid 18091:tid 18091] [client 162.158.63.28:12134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ecuablue.farm"] [uri "/docker/.env.local"] [unique_id "abzfXyIGOU36JgirkHkQ6QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:27:29
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:27:16.779416 2026] [security2:error] [pid 11109:tid 11109] [client 162.158.63.28:10456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marcosbarraza.net"] [uri "/site/.env"] [unique_id "abzatBbnOpDRwSMLNG9QyQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:43:54
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:43:49.173151 2026] [security2:error] [pid 28845:tid 28845] [client 162.158.63.28:10228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bryteandbroderick.org"] [uri "/.env2"] [unique_id "abvTZUBi4245gfZ8DNjCWwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:27:51
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:27:45.285212 2026] [security2:error] [pid 1817:tid 1830] [client 162.158.63.28:9539] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cynosureirrigation.com.cynosureinternetservices.com"] [uri "/.env_config"] [unique_id "abvPoZYccVtTjQgBThGQ3AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 09:32:45
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:32:38.007363 2026] [security2:error] [pid 30798:tid 30798] [client 162.158.63.28:10826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.unwaved.kvaziri.com"] [uri "/root/.env"] [unique_id "abvCtnBdN4D1P-bJI8BPOAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack