๐บ๐ธ
TPI-Abuse
2026-05-15 10:13:18
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 06:13:10.483585 2026] [security2:error] [pid 8924:tid 8924] [client 162.158.79.113:10893] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mnalabama.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mnalabama.com"] [uri "/db_backup.sql"] [unique_id "agbxtjKlM8nMOfJ1z2aTeAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 07:05:17
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-04 02:05:15
(2 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 10:33:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 06:33:22.699904 2026] [security2:error] [pid 15405:tid 15405] [client 162.158.79.113:13564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.plava.org"] [uri "/.env1"] [unique_id "acZc8kaVwYJARLUpiMkF0QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 04:16:49
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 00:16:42.062742 2026] [security2:error] [pid 24629:tid 24629] [client 162.158.79.113:11409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "97films.media"] [uri "/.env.development"] [unique_id "acYEqkEd1k_2BRGzVlfJ0gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 17:41:10
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 13:40:50.714140 2026] [security2:error] [pid 21390:tid 21420] [client 162.158.79.113:9242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.j-and-t.net"] [uri "/.env.development"] [unique_id "acVvor5n0ktli8R8Qo3CLwAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 13:30:52
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 09:30:40.739328 2026] [security2:error] [pid 8803:tid 8803] [client 162.158.79.113:10232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oxyveg.com"] [uri "/.env.production.bak"] [unique_id "acU1AMRhK7cDPQIWTuoGNQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 16:08:50
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 12:08:30.181417 2026] [security2:error] [pid 12056:tid 12056] [client 162.158.79.113:9918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garthp.com"] [uri "/.env.json"] [unique_id "acQIflB4X8nX-NuW9hrtjgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-22 03:05:39
(2 months ago)
Scanning/Probing (32)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-21 02:06:19
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-19 08:05:53
(2 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 17:08:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 12:08:42.641987 2026] [security2:error] [pid 28879:tid 28879] [client 162.158.79.113:13444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ahuramazda.com"] [uri "/.env.test"] [unique_id "aY9amrmuJq0JmcltE4D-zAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
swk
2025-09-22 21:35:04
(8 months ago)
162.158.79.113 - - [23/Sep/2025:05:35:03 +0800] "HEAD /home HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Window ...
show more
162.158.79.113 - - [23/Sep/2025:05:35:03 +0800] "HEAD /home HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.36"
162.158.79.113 - - [23/Sep/2025:05:35:03 +0800] "HEAD /bc HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.6422.60 Safari/537.36 Edg/125.0.2535.51"
162.158.79.113 - - [23/Sep/2025:05:35:03 +0800] "HEAD / HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.56 Mobile Safari/537.36"
...
show less
Hacking
Web App Attack
Anonymous
2025-08-27 07:02:50
(9 months ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
Web App Attack
SSH
๐บ๐ธ
creations.works
2025-08-14 07:42:34
(9 months ago)
Blocked by UFW on vds [80/tcp]
Source port: 42274
TTL: 58
Packet length: 60
TOS: 0x00
This report w ...
show more
Blocked by UFW on vds [80/tcp]
Source port: 42274
TTL: 58
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack