๐ง๐ช
madeit
2026-08-31 16:52:21
(1 day ago)
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-25 18:40:08
(1 week ago)
Web App Attack
๐ง๐ช
madeit
2026-08-06 05:06:10
(3 weeks ago)
Web App Attack
๐ฌ๐ง
OptimusGO
2026-07-20 22:24:11
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-20 23:24:11 UTC
Log evidence:
162.158.63.43 - - [20/Jul/2026:23:24:05 +0100] "GET /v2/_catalog HTTP/1.1" 404 118 "-" "Mozilla/5.0 (l9scan/2.0.534323e2835313e27363e2237313; +https://leakix.net)"
07/20/2026-23:24:05.803147 [**] [1:2049255:1] ET SCAN LeakIX Inbound User-Agent [**] [Classification: Misc activity] [Priority: 3] {TCP} 162.158.63.43:10571 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐ณ๐ด
jad-abuse
2026-07-04 02:36:25
(1 month ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ssh_keys. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: ssh_keys. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐ฌ๐ง
CrystalMaker
2026-07-02 01:31:51
(2 months ago)
Vulnerability scan - GET /ops/status HTTP/2.0
Hacking
๐ฉ๐ช
acadeova
2026-05-01 12:01:16
(4 months ago)
๐จ Recon detected (nft drop)
SRC=162.158.63.43
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.63.43
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
Anonymous
2026-04-08 04:18:32
(4 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐จ๐ฆ
Blinker73
2026-03-24 12:01:30
(5 months ago)
162.158.63.43 - - [24/Mar/2026:07:58:14 -0400] "GET /.env.example HTTP/1.1" 301 162 "-" "-"
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 10:07:25
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 06:07:20.037054 2026] [security2:error] [pid 20503:tid 20503] [client 162.158.63.43:11164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.whaletailpuckerbutt.com"] [uri "/.env.staging"] [unique_id "ab-_WGrBmBd2FLZU48d0WAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 16:24:23
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 12:24:15.548578 2026] [security2:error] [pid 2723:tid 2723] [client 162.158.63.43:10323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blindshine.com"] [uri "/.env.local"] [unique_id "ab7GL4HUMe7P8XMp4eAHmwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 05:55:41
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 01:55:32.018243 2026] [security2:error] [pid 4656:tid 4678] [client 162.158.63.43:12322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.alred.net"] [uri "/.env.staging"] [unique_id "ab4y1AXt7yTJhRPOWRHoogAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 03:08:20
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 23:08:11.551605 2026] [security2:error] [pid 4056:tid 4056] [client 162.158.63.43:12823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kerrywelt.com"] [uri "/.env"] [unique_id "ab4Lmx-u8QY04f3I9qIzPgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:56:18
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:56:13.684466 2026] [security2:error] [pid 31477:tid 31477] [client 162.158.63.43:11149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.whaleyhouse.net"] [uri "/.env.json"] [unique_id "ab0LrfxAL-xn7qC0PnBOMwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:03:14
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:03:10.795469 2026] [security2:error] [pid 28295:tid 28295] [client 162.158.63.43:14215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.30daysout.com"] [uri "/.envrc"] [unique_id "abzxLgxz-7z_Q3vbqO0WPwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack