๐ฉ๐ช
acadeova
2026-06-25 05:10:44
(2 days ago)
๐จ Recon detected (nft drop)
SRC=162.158.63.58
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.63.58
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
SiliSoftware
2026-06-25 00:50:41
(2 days ago)
/.pypirc
Web App Attack
๐ฉ๐ช
netclix.gr
2026-06-11 04:11:23
(2 weeks ago)
(security_scan) Sensitive File Scan Blocked 162.158.63.58 (US/United States/-): 1 in the last 4600 s ...
show more
(security_scan) Sensitive File Scan Blocked 162.158.63.58 (US/United States/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 162.158.63.58 - - [11/Jun/2026:07:11:16 +0300] "GET /.git/config HTTP/2.0" 404 532 "-" "Mozilla/5.0 (l9scan/2.0.7373e2537313e27363e2237313; +https://leakix.net)" "206.81.12.187"'/error_docs/404.html' '' '/opt/psa/admin/htdocs'
show less
Port Scan
๐ต๐ฑ
IROK
2026-03-30 21:28:38
(2 months ago)
Malware/WebShell Scan blocked by ModSecurity
...
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-21 07:26:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 03:26:47.885149 2026] [security2:error] [pid 29051:tid 29051] [client 162.158.63.58:13995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agkgt.org"] [uri "/.envrc"] [unique_id "ab5INzNX7Mii-a4WB-b5jwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 06:16:11
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 02:16:06.118800 2026] [security2:error] [pid 4084148:tid 4084148] [client 162.158.63.58:12867] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nagareinkpaper.com"] [uri "/.env.staging"] [unique_id "ab43pg9mDVP3BgfuCLHimQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 00:26:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:26:48.550296 2026] [security2:error] [pid 17247:tid 17247] [client 162.158.63.58:11073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dominionfinancialadvisors.com"] [uri "/.env.test"] [unique_id "ab3lyFoRwgIliKOjfNm6_gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 00:04:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:04:12.148490 2026] [security2:error] [pid 9343:tid 9343] [client 162.158.63.58:10915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.developerdove.com"] [uri "/var/www/html/.env"] [unique_id "ab3gfPpgF1Tq61MD9HKKFQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 00:58:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:57:58.369878 2026] [security2:error] [pid 18334:tid 18334] [client 162.158.63.58:12202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.emailaegis.com"] [uri "/.env_config"] [unique_id "abyblr4APXCg9gBXIsibAAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:37:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:37:44.434685 2026] [security2:error] [pid 19258:tid 19258] [client 162.158.63.58:13932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cleaningsuppliescr.com"] [uri "/root/.env"] [unique_id "abvgCEG2qHevk7-oXDBkSQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:22:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:22:30.838914 2026] [security2:error] [pid 32227:tid 32227] [client 162.158.63.58:14105] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ladylilacfarm.com"] [uri "/docker/.env"] [unique_id "abvcdiyXEfJ5oMDvECcwAwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:04:02
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:03:50.997436 2026] [security2:error] [pid 13912:tid 13912] [client 162.158.63.58:11375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gibraltar-boat-registration.com"] [uri "/.env.orig"] [unique_id "abvYFimzXmtDlIMVjSUaYAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 09:57:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:57:52.096134 2026] [security2:error] [pid 18304:tid 18304] [client 162.158.63.58:9649] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "n4fh.com"] [uri "/.env_settings"] [unique_id "abvIoEYS5tgw3Ug-KzshVAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 07:56:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 03:56:02.330984 2026] [security2:error] [pid 11994:tid 11994] [client 162.158.63.58:14311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bristar-usa.com"] [uri "/home/.env"] [unique_id "abusEn9PEO1-tDxajeO64wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 06:24:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 02:24:07.497241 2026] [security2:error] [pid 19204:tid 19204] [client 162.158.63.58:13612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fundaciondamashcc.org.ec"] [uri "/.env"] [unique_id "abuWh51yHs-rvE7pzHtzCgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack