πΊπΈ
TPI-Abuse
2026-05-15 08:37:25
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:37:20.336418 2026] [security2:error] [pid 18949:tid 18949] [client 162.158.78.228:12035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oceansgift.com"] [uri "/.env.development"] [unique_id "agbbQNtYqYEaDCOPJNrcqAAAAAg"], referer: https://www.google.com/search?q=oceansgift.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
wimaxnz
2026-04-27 00:49:56
(1 month ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
πΊπΈ
wimaxnz
2026-04-18 00:44:13
(1 month ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
πΊπΈ
mnsf
2026-04-07 10:05:20
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-04-04 10:05:37
(2 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-03-31 05:05:51
(2 months ago)
Scanning/Probing (18)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-27 13:05:32
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 09:03:28.595214 2026] [security2:error] [pid 31624:tid 31736] [client 162.158.78.228:10274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kellenlee.com"] [uri "/.env.old"] [unique_id "acaAIIntGU8_am6dPAK6YgAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-27 04:26:46
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 00:26:25.067415 2026] [security2:error] [pid 4229:tid 4229] [client 162.158.78.228:11869] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wholesaleglassjars.com"] [uri "/.env.tmp"] [unique_id "acYG8asCqhoT8r9nfHGM2gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-03-27 03:05:52
(2 months ago)
Scanning/Probing (16)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-26 14:58:49
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 10:58:30.916042 2026] [security2:error] [pid 18333:tid 18353] [client 162.158.78.228:13757] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.aaenroll.com"] [uri "/.env2"] [unique_id "acVJlq7upkVpT_39pbfIiwAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-26 14:02:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 10:02:05.025351 2026] [security2:error] [pid 32100:tid 32100] [client 162.158.78.228:9370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lakesidedetectiveagency.com"] [uri "/public/.env"] [unique_id "acU8XQvB-l-IKTclkdqeugAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-26 08:20:48
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 04:20:37.292076 2026] [security2:error] [pid 9315:tid 9315] [client 162.158.78.228:9862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.arklatexds.com"] [uri "/.env_config"] [unique_id "acTsVZBe8BOoj2DMLRQ4BAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-26 04:48:46
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 00:48:36.525558 2026] [security2:error] [pid 28064:tid 28090] [client 162.158.78.228:14035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hoffmanandassoc.com"] [uri "/.env_backup"] [unique_id "acS6pHI60uAMpArvlInilQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-25 21:28:07
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 17:27:43.468803 2026] [security2:error] [pid 27735:tid 27735] [client 162.158.78.228:10240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.intermixxnet.independentmusicconference.com"] [uri "/.git/HEAD"] [unique_id "acRTT0zxDmWr9SuhJ_VYfgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-25 15:53:09
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 11:52:16.868436 2026] [security2:error] [pid 30682:tid 30682] [client 162.158.78.228:14291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.itre.org"] [uri "/web/.env"] [unique_id "acQEsMvhZVJ_ItSC_tpzuAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack