๐ฌ๐ง
sandra361
2026-09-05 08:11:31
(1 week ago)
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=162.1 ...
show more
Port scan detected: 6 attempts across 1 port (443). | Evidence: REAPER_TARPIT: IN=enp1s0f0 SRC=162.158.63.98 LEN=40 TOS=0x00 PREC=0x00 TTL=55 ID=15490 DF PROTO=TCP SPT=12803 DPT=443 WINDOW=65535 RES=0x00 ACK URGP=0
show less
Port Scan
๐บ๐ธ
InfraGuardAPI
2026-08-22 21:01:47
(3 weeks ago)
[critical] middleware_block | reason=scanner_signature_detected | path=/api/auth/login | ua=Mozilla/ ...
show more
[critical] middleware_block | reason=scanner_signature_detected | path=/api/auth/login | ua=Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36
show less
Port Scan
Hacking
๐ฎ๐ฉ
securejdprop
2026-08-21 06:52:25
(4 weeks ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐ง๐ช
madeit
2026-08-06 01:58:12
(1 month ago)
Web App Attack
Anonymous
2026-07-30 12:20:38
(1 month ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ฉ๐ช
ValtonTahiri
2026-07-16 20:30:31
(2 months ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=162.158.63.98; proto=TCP; source_port=12170; target_port=8443; flags=SYN
show less
Port Scan
๐บ๐ธ
Lee Daniel
2026-06-25 21:52:50
(2 months ago)
162.158.63.98 - - [25/Jun/2026:17:52:48 -0400] "GET /auth/login HTTP/1.1" 404 33213 "-" "Mozilla/5.0 ...
show more
162.158.63.98 - - [25/Jun/2026:17:52:48 -0400] "GET /auth/login HTTP/1.1" 404 33213 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.158.63.98 - - [25/Jun/2026:17:52:49 -0400] "GET /auth/login HTTP/1.1" 404 33211 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.158.63.98 - - [25/Jun/2026:17:52:49 -0400] "GET /account/login HTTP/1.1" 404 33214 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.158.63.98 - - [25/Jun/2026:17:52:49 -0400] "GET /account/login HTTP/1.1" 404 33217 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.158.63.98 - - [25/Jun/2026:17:52:49 -0400] "GET /graphql HTTP/1.1" 404 33199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Sa
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
OptimusGO
2026-06-22 02:44:13
(2 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-22 03:44:13 UTC
Log evidence:
06/22/2026-03:44:06.354688 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 162.158.63.98:12009 -> 185.127.18.66:8443
show less
Port Scan
Brute-Force
๐ต๐ฑ
IROK
2026-04-03 07:35:17
(5 months ago)
Malware/WebShell Scan blocked by ModSecurity
...
Hacking
๐จ๐ฆ
Blinker73
2026-03-24 12:01:11
(5 months ago)
162.158.63.98 - - [24/Mar/2026:07:58:14 -0400] "GET /.env.production.local HTTP/1.1" 301 162 "-" "-"
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 16:39:49
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 12:39:45.730412 2026] [security2:error] [pid 17250:tid 17250] [client 162.158.63.98:11971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.femalegamblers.org"] [uri "/config/.env.local"] [unique_id "ab7J0WCXEJxJDWG5aq_GDwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 03:31:20
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 23:31:12.638297 2026] [security2:error] [pid 32754:tid 32754] [client 162.158.63.98:13327] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.farmers123.com"] [uri "/public/.env"] [unique_id "ab4RAKBuE4t5Dk53Ykc2OwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:12:03
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:11:57.425475 2026] [security2:error] [pid 13951:tid 13951] [client 162.158.63.98:9471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.amazedbyu.com"] [uri "/.env.production.local"] [unique_id "ab3wXXI1yhq0FdopFEC5OgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:55:02
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:54:55.556121 2026] [security2:error] [pid 25870:tid 25870] [client 162.158.63.98:14285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.whaleyhouse.net"] [uri "/.env.test"] [unique_id "ab0LX1oqEKjZeTAC5Xa6bwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 08:08:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:08:18.412069 2026] [security2:error] [pid 15295:tid 15362] [client 162.158.63.98:10659] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.northtexaslive.com"] [uri "/.env.bak"] [unique_id "ab0AclpJ0R9QYe1Sx-s2FQAAAYQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack