๐ฉ๐ช
ghostwarriors
2026-06-25 09:50:09
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 12:32:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 08:32:19.166387 2026] [security2:error] [pid 9946:tid 10052] [client 162.158.78.137:26052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "getairborne.com"] [uri "/.env.local"] [unique_id "ajU2078GBx2_dwUTSKjNCAAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 12:01:01
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 08:00:53.457063 2026] [security2:error] [pid 17314:tid 17314] [client 162.158.78.137:13609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fattoria-rendena.it"] [uri "/.env.production"] [unique_id "agcK9RaqIFbIDyr0E8UlCAAAAAA"], referer: https://www.google.com/search?q=fattoria-rendena.it
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 11:05:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:05:26.570967 2026] [security2:error] [pid 26180:tid 26180] [client 162.158.78.137:13826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fourhillsco.grupoporvenir.com"] [uri "/.env"] [unique_id "agb99qlqU-hxeh1VrGGcfgAAAAE"], referer: https://www.google.com/search?q=www.fourhillsco.grupoporvenir.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:21:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:20:52.202336 2026] [security2:error] [pid 12811:tid 12811] [client 162.158.78.137:13477] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hills-tax.willowbrookins.com"] [uri "/.env.php"] [unique_id "agbldCdrx70lMtR5tCd72AAAAGs"], referer: https://www.google.com/search?q=www.hills-tax.willowbrookins.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 01:18:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 21:18:44.522373 2026] [security2:error] [pid 1286:tid 1286] [client 162.158.78.137:9872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.humans2humans.org"] [uri "/.env"] [unique_id "agZ0dBVN3-8wwxhFMnaq_QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-09 14:28:07
(1 month ago)
[Sat May 09 16:28:06.495982 2026] [authz_core:error] [pid 21293] [client 162.158.78.137:9739] AH0163 ...
show more
[Sat May 09 16:28:06.495982 2026] [authz_core:error] [pid 21293] [client 162.158.78.137:9739] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat May 09 16:28:06.620234 2026] [authz_core:error] [pid 21293] [client 162.158.78.137:9739] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat May 09 16:28:06.742549 2026] [authz_core:error] [pid 21293] [client 162.158.78.137:9739] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 02:05:47
(2 months ago)
Scanning/Probing (23)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 13:47:27
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 09:47:22.244636 2026] [security2:error] [pid 31111:tid 31111] [client 162.158.78.137:12834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.freemanfoundationcle.org"] [uri "/config/.env.local"] [unique_id "acaKaqWB84c8IS6-xZIuUAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 13:03:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 09:02:48.169043 2026] [security2:error] [pid 31625:tid 31667] [client 162.158.78.137:11825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kellenlee.com"] [uri "/.env.docker"] [unique_id "acZ_-J8VJHgw6bAdmlEW3wAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 19:47:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 15:46:44.916292 2026] [security2:error] [pid 32377:tid 32377] [client 162.158.78.137:14056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bowdens-landing.com"] [uri "/docker/.env.local"] [unique_id "acWNJPKSabpTF1AKtPyjDwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 12:27:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 08:26:37.994922 2026] [security2:error] [pid 8709:tid 8709] [client 162.158.78.137:10301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.proboundary.com"] [uri "/.env.save"] [unique_id "acUl_VflZa_p23Sezd0k8wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 21:28:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 17:27:24.388380 2026] [security2:error] [pid 28270:tid 28270] [client 162.158.78.137:11697] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.intermixxnet.independentmusicconference.com"] [uri "/config/.env"] [unique_id "acRTPBpIb1F3mzC9bFreHAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 13:05:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 09:04:49.566728 2026] [security2:error] [pid 6376:tid 6376] [client 162.158.78.137:9264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anniversaryprintednapkins.com"] [uri "/app/.env"] [unique_id "acPdcTHuweHpwueaI8-17AAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-03-23 06:13:49
(3 months ago)
8 attacks on PHP URLs:
POST /php/connector.minimal.php HTTP/1.1
Web App Attack