๐ง๐ช
madeit
2026-09-06 05:34:51
(11 hours ago)
Web App Attack
๐ฉ๐ช
Blexyel
2026-08-23 08:15:43
(2 weeks ago)
162.158.63.38 - - [23/Aug/2026:10:15:42 +0200] "GET /.git/config HTTP/1.1" 200 264 "-" "Mozilla/5.0 ...
show more
162.158.63.38 - - [23/Aug/2026:10:15:42 +0200] "GET /.git/config HTTP/1.1" 200 264 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "136.243.2.38"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 01:09:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 21:09:48.518525 2026] [security2:error] [pid 20132:tid 20132] [client 162.158.63.38:26062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coast22.net"] [uri "/.env.test"] [unique_id "alrSXGJiSXWDYbsj8RDBdgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-09 04:09:26
(1 month ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฌ๐ง
OptimusGO
2026-06-22 07:09:51
(2 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-22 08:09:50 UTC
Log evidence:
162.158.63.38 - - [22/Jun/2026:08:09:49 +0100] "GET /media/wp-includes/wlwmanifest.xml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
162.158.63.38 - - [22/Jun/2026:08:09:49 +0100] "GET /wp2/wp-includes/wlwmanifest.xml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
162.158.63.38 - - [22/Jun/2026:08:09:49 +0100] "GET /site/wp-includes/wlwmanifest.xml HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
show less
Port Scan
Brute-Force
Anonymous
2026-06-11 00:09:01
(2 months ago)
Web App Attack
Brute-Force
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-05-21 04:09:43
(3 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 05:38:40
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 01:38:36.287451 2026] [security2:error] [pid 9274:tid 9296] [client 162.158.63.38:13105] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotelpuertadelsolcr.com"] [uri "/private/.env"] [unique_id "ab4u3J5irHLi_aK9wuw7eQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:08:03
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:07:55.103717 2026] [security2:error] [pid 26689:tid 26689] [client 162.158.63.38:12239] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mariarozella.com"] [uri "/www/.env"] [unique_id "ab4Zmz9M26WCy4qc47ZAdAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:25:13
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:25:08.832096 2026] [security2:error] [pid 29775:tid 29775] [client 162.158.63.38:13870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bacpool.com"] [uri "/.git/refs/heads/main"] [unique_id "ab0EZDmwGH-ltdsIFEKrlgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:20:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:20:37.164306 2026] [security2:error] [pid 21598:tid 21598] [client 162.158.63.38:13392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.michael-beasley.com"] [uri "/.env.production"] [unique_id "abzZJTdybZp3H84alcbW6AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:50:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:50:25.024901 2026] [security2:error] [pid 3580:tid 3580] [client 162.158.63.38:11338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rlysue.com"] [uri "/www/.env"] [unique_id "aby18Yfa6I9EJPH6AQ4prAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 00:10:56
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:10:37.744152 2026] [security2:error] [pid 21091:tid 21091] [client 162.158.63.38:13153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.slartibartfast.com"] [uri "/.env.orig"] [unique_id "abyQfa1bp8MGhpsGhqCCagAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:58:05
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:58:00.161381 2026] [security2:error] [pid 14631:tid 14631] [client 162.158.63.38:12068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.janner.us"] [uri "/var/www/.env"] [unique_id "abvkyDoiE2kKVjVTmOcWpwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:09:02
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:08:54.841889 2026] [security2:error] [pid 19133:tid 19133] [client 162.158.63.38:9970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.belgiophar.com"] [uri "/.env.container"] [unique_id "abvZRpd7W9qNk1Nz5WJu7wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack