๐บ๐ธ
TPI-Abuse
2026-05-15 11:05:55
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:05:34.800283 2026] [security2:error] [pid 25754:tid 25754] [client 162.158.78.102:9234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fourhillsco.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fourhillsco.com"] [uri "/backup.sql"] [unique_id "agb9_knj62VYpojCDxkBUAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wimaxnz
2026-04-19 05:52:47
(1 month ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
mnsf
2026-03-31 16:05:26
(2 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 16:46:46
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 12:46:39.726697 2026] [security2:error] [pid 18792:tid 18792] [client 162.158.78.102:9694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coolex.cloudex.link"] [uri "/.env_secret"] [unique_id "aca0b9Q5OkksXLbgB72-vgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 14:01:01
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 10:00:51.867411 2026] [security2:error] [pid 11410:tid 11410] [client 162.158.78.102:10113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.skulldump.com"] [uri "/srv/.env"] [unique_id "acaNk-R-8d-3-TVNhtCWTQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 18:22:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 14:22:32.584827 2026] [security2:error] [pid 4933:tid 4933] [client 162.158.78.102:13780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gormish.org"] [uri "/var/www/html/.env"] [unique_id "acV5aOUnvnFIuddvbf211AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 04:24:46
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 00:24:20.751243 2026] [security2:error] [pid 18391:tid 18391] [client 162.158.78.102:10118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.lloydprins.com"] [uri "/www/.env"] [unique_id "acS09LNX06vyHuhLJSszGgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 20:47:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 16:47:10.360665 2026] [security2:error] [pid 25509:tid 25509] [client 162.158.78.102:14196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.twccsolutions.com"] [uri "/.env_secret"] [unique_id "acRJzh-oIZCiUvj0xHvVjAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 17:37:07
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 13:36:26.849970 2026] [security2:error] [pid 24212:tid 24212] [client 162.158.78.102:10834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cwidisplays.com"] [uri "/.env.bak"] [unique_id "acQdGtfC_HrVVdhXqCglHwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-03-21 19:02:25
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mnsf
2026-03-18 13:06:31
(2 months ago)
Scanning/Probing (57)
Brute-Force
Web App Attack
๐ฆ๐บ
oncord
2026-03-01 13:14:36
(3 months ago)
Form spam
Web Spam
๐บ๐ธ
mawan
2026-02-27 09:14:55
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฆ๐บ
oncord
2026-01-02 00:34:12
(5 months ago)
Form spam
Web Spam
๐บ๐ธ
mawan
2025-11-02 17:21:48
(7 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack