๐บ๐ธ
TPI-Abuse
2026-05-15 11:04:23
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:03:53.768157 2026] [security2:error] [pid 28036:tid 28036] [client 162.158.79.35:12829] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jhonbens.com"] [uri "/.env.development.local"] [unique_id "agb9mQzD8gTXtTsVkt0sdQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:02:53
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:02:45.345797 2026] [security2:error] [pid 29787:tid 29787] [client 162.158.79.35:13420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vendor21.com"] [uri "/.env.local"] [unique_id "agbFFZJza2BDd-a3E8P7_QAAABM"], referer: https://www.google.com/search?q=vendor21.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-21 22:02:02
(1 month ago)
Auto-ban: >3000 req/min op 2026-04-21
Web App Attack
SSH
Hacking
๐ฎ๐ฉ
RasyiidWho
2026-04-15 11:13:29
(1 month ago)
ip112.20 . 162.158.79.35 - - [15/Apr/2026:18:13:28 +0700] "GET /wp-login.php HTTP/2.0" 404 146 "-" " ...
show more
ip112.20 . 162.158.79.35 - - [15/Apr/2026:18:13:28 +0700] "GET /wp-login.php HTTP/2.0" 404 146 "-" "BlackVeil-Security-Scanner/5.1.0 (https://blackveilsecurity.com; [email protected] )"
...
show less
DDoS Attack
Brute-Force
Port Scan
Bad Web Bot
Web App Attack
SSH
๐บ๐ธ
mnsf
2026-04-06 02:05:18
(2 months ago)
Scanning/Probing (22)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 01:05:11
(2 months ago)
Scanning/Probing (19)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-01 01:05:19
(2 months ago)
Scanning/Probing (27)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-31 00:05:36
(2 months ago)
Scanning/Probing (21)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-29 23:05:20
(2 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-03-29 19:11:18
(2 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 02:44:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 22:44:33.096644 2026] [security2:error] [pid 27173:tid 27173] [client 162.158.79.35:11482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.whitmarshinc.com"] [uri "/www/.env"] [unique_id "acXvEbLm873q8E3B_AtyUgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 23:29:41
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 19:29:34.727295 2026] [security2:error] [pid 13579:tid 13579] [client 162.158.79.35:9986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stage.cormanleigh.com"] [uri "/www/.env"] [unique_id "acXBXoU4IRT0SsXkYJwYyAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 23:07:38
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 19:07:30.503016 2026] [security2:error] [pid 19907:tid 19907] [client 162.158.79.35:12532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.spottedeaglearts.com"] [uri "/site/.env"] [unique_id "acW8MhV2MoUNo8wbTgQvYwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 19:48:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 15:48:28.065616 2026] [security2:error] [pid 7182:tid 7182] [client 162.158.79.35:10666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bowdens-landing.com"] [uri "/.env.prod"] [unique_id "acWNjAYlh7ja26tOIzuaOAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 14:58:45
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 10:58:10.674131 2026] [security2:error] [pid 18333:tid 18341] [client 162.158.79.35:10287] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.aaenroll.com"] [uri "/.env.staging"] [unique_id "acVJgq7upkVpT_39pbfGaAAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack