๐ง๐ช
madeit
2026-08-09 04:23:20
(3 weeks ago)
Web App Attack
๐บ๐ธ
THP SecurityTeam
2026-07-20 16:07:00
(1 month ago)
A successful device code phishing attack resulted in an unauthorized access attempt from this IP. T ...
show more
A successful device code phishing attack resulted in an unauthorized access attempt from this IP. There is a bad actor at this IP. Event happened 7/17/2026 at 12:44:44 pm ET.
show less
Hacking
๐บ๐ธ
mnsf
2026-06-16 00:07:03
(2 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
xxkodedxx
2026-05-26 22:36:03
(3 months ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: US / AS13335 Cloudflare, Inc.
Active: 22:35:51 UTC
Volume: 1 HTTP req
Probed: /wp-admin/install.php?step=1
Status mix: 444ร1
UA: "http://ztx-lab.com/wp-admin/install.php?step=1"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:22:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:22:22.533986 2026] [security2:error] [pid 479:tid 479] [client 162.158.79.192:13090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.elearning.nextngnr.com"] [uri "/sftp-config.json"] [unique_id "agblzrxg4TcBmIB75uaBdQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 09:57:29
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 05:57:22.942436 2026] [security2:error] [pid 15241:tid 15248] [client 162.158.79.192:10489] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beelineproductions.com"] [uri "/.git/config"] [unique_id "af8FArN_0r_fkSHAe8JkwQAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-24 03:05:37
(4 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-21 22:00:19
(4 months ago)
Auto-ban: >3000 req/min op 2026-04-21
Web App Attack
SSH
Hacking
๐บ๐ธ
mnsf
2026-04-20 13:08:45
(4 months ago)
Login Too Frequent (8)
Brute-Force
Web App Attack
๐ช๐ธ
bohl-aiG5aef
2026-04-06 10:32:42
(4 months ago)
Suricata Alert [SID:2031502] ET INFO Request to Hidden Environment File - Inbound
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-27 02:35:11
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 22:34:42.956395 2026] [security2:error] [pid 1366:tid 1366] [client 162.158.79.192:11705] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.avanticaffe.com"] [uri "/.env.production.local"] [unique_id "acXswotS4SKe3IV0bv9p0QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 17:37:46
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 13:37:27.851287 2026] [security2:error] [pid 15985:tid 15985] [client 162.158.79.192:13408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cnphilos.com"] [uri "/www/.env"] [unique_id "acVu12DydF1643aOubi6eQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 13:29:15
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 09:28:50.496553 2026] [security2:error] [pid 19979:tid 19979] [client 162.158.79.192:11489] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.silvermoonpizza.com"] [uri "/core/.env"] [unique_id "acU0klp3zZzj0b43EbP6fwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 12:28:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 08:27:58.247008 2026] [security2:error] [pid 10283:tid 10283] [client 162.158.79.192:13883] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.proboundary.com"] [uri "/.env.old"] [unique_id "acUmTmpcNvRHK3Qrak_tnAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 01:28:58
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 21:28:50.113043 2026] [security2:error] [pid 7882:tid 7882] [client 162.158.79.192:13252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.carphotoframes.biz"] [uri "/.env.orig"] [unique_id "acSL0gJGXa8sqOxPuT0CkwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack