๐ซ๐ท
dynamix
2026-10-06 21:48:51
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-10-04 23:45:15
(2 days ago)
Web App Attack
๐ซ๐ท
dynamix
2026-09-25 19:25:32
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-01 01:33:10
(1 month ago)
Web App Attack
๐ณ๐ฑ
COMPLEX
2026-07-10 01:37:58
(2 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐ณ๐ฑ
COMPLEX
2026-06-26 03:21:53
(3 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐บ๐ธ
HJ5Ss4Ju
2026-06-09 08:34:57
(3 months ago)
WordPress XMLRPC scan :: 162.158.63.68 - - [09/Jun/2026:08:34:56 0000] "GET /xmlrpc.php HTTP/1.1" 4 ...
show more
WordPress XMLRPC scan :: 162.158.63.68 - - [09/Jun/2026:08:34:56 0000] "GET /xmlrpc.php HTTP/1.1" 405 53 "https://mockbox.net/xmlrpc.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
acadeova
2026-05-31 01:23:18
(4 months ago)
๐จ Recon detected (nft drop)
SRC=162.158.63.68
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.63.68
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฉ๐ช
Zydzy
2026-05-17 09:53:56
(4 months ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-exploit.
Web App Attack
๐ต๐ฑ
IROK
2026-03-31 00:13:54
(6 months ago)
Malware/WebShell Scan blocked by ModSecurity
...
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-21 00:25:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:25:20.007907 2026] [security2:error] [pid 17678:tid 17678] [client 162.158.63.68:12773] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.restaurantehaowey.com"] [uri "/site/.env"] [unique_id "ab3lcHaVe2Z-IknTBjFOyAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
yukon.ca
2026-03-20 17:50:34
(6 months ago)
Web Server Enforcement Violation: Sensitive Configuration File Disclosure
Port:80
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-03-20 08:56:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:56:33.148316 2026] [security2:error] [pid 29713:tid 29713] [client 162.158.63.68:9958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.whaleyhouse.net"] [uri "/.env.orig"] [unique_id "ab0LwdlxptCefcqjRl4wiAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:34:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:34:01.525805 2026] [security2:error] [pid 18879:tid 18879] [client 162.158.63.68:11936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.celltechs.net"] [uri "/home/.env"] [unique_id "ab0GeXFNaCqLZKlHKqitZAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:57:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:56:56.067616 2026] [security2:error] [pid 4107:tid 4129] [client 162.158.63.68:12473] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cynosurerealestatemedia.com.cynosureinternetservices.com"] [uri "/.env.dist"] [unique_id "aby3ePdclhjUUdh0FRUY7QAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack