πΊπΈ
mawan
2026-08-21 23:46:39
(6 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
π¨πΏ
sajmon0011
2026-08-17 22:59:21
(1 week ago)
162.158.88.120 - - [18/Aug/2026:00:59:20 +0200] "GET /.git/config HTTP/2.0" 404 196 "-" "Mozilla/5.0 ...
show more
162.158.88.120 - - [18/Aug/2026:00:59:20 +0200] "GET /.git/config HTTP/2.0" 404 196 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Web App Attack
π«π·
Little Iguana
2026-08-17 22:49:37
(1 week ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
πΊπΈ
TPI-Abuse
2026-08-17 22:47:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 18:47:25.563844 2026] [security2:error] [pid 2423:tid 2423] [client 162.158.88.120:13458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.boat-registration-croatia.com"] [uri "/.git/HEAD"] [unique_id "aoOPfZvvAKEUHG7uBWSxHQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 09:18:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:18:40.768075 2026] [security2:error] [pid 5467:tid 5467] [client 162.158.88.120:13388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.concentricsteel.com"] [uri "/.git/HEAD"] [unique_id "aoLR8P9I-TNTfnUGlUJ5KwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 08:57:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:57:31.638578 2026] [security2:error] [pid 27716:tid 27716] [client 162.158.88.120:12997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guavaroad.com"] [uri "/.git/HEAD"] [unique_id "aoLM-3kIEJdnNW_G6TDfTgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 05:04:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:04:25.903580 2026] [security2:error] [pid 29999:tid 29999] [client 162.158.88.120:13650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.africanwisdominimageandproverb.com"] [uri "/.git/HEAD"] [unique_id "aoKWWWB41rkhE7gdvtAsMwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-08-17 00:27:11
(1 week ago)
[MonAug1702:27:05.7246462026][security2:error][pid615460:tid615481][client162.158.88.120:0]ModSecuri ...
show more
[MonAug1702:27:05.7246462026][security2:error][pid615460:tid615481][client162.158.88.120:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.spazi-web-hosting.artisteer-italia.org\"][uri\"/.git/HEAD\"][unique_id\"aoJVWY1jr8GzHriVQC5jwQAAARE\"]
show less
Port Scan
Brute-Force
Web App Attack
π«π·
dynamix
2026-08-16 23:28:24
(1 week ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 10:45:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 06:45:12.454655 2026] [security2:error] [pid 1603:tid 1632] [client 162.158.88.120:12160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ennerdalebridge.com"] [uri "/.git/config"] [unique_id "aoGUuIfWgm13WWpGjrNFGAAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-14 05:20:10
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 01:20:03.980610 2026] [security2:error] [pid 2311285:tid 2311297] [client 162.158.88.120:13423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.isa-logistics.oplconnect.com"] [uri "/.git/config"] [unique_id "an6lg_0K_DMwAgGV3RNAjQAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-13 09:54:02
(2 weeks ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-12 22:43:21
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 18:43:13.994143 2026] [security2:error] [pid 745149:tid 745149] [client 162.158.88.120:12521] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebradleyclinic.com.jbcllcnet.com"] [uri "/.git/config"] [unique_id "anz3AVdH5bwX1vP903Q0PwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-11 22:48:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 18:48:30.126276 2026] [security2:error] [pid 11748:tid 11748] [client 162.158.88.120:9963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mackdaddy.smoothg.com"] [uri "/.git/HEAD"] [unique_id "anumvu3IrnkFzBCD4WfOuQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-11 08:38:38
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 04:38:31.764334 2026] [security2:error] [pid 817:tid 817] [client 162.158.88.120:12382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.handankoc.net"] [uri "/.git/config"] [unique_id "anrfh93IixqLrwR1S6JQvwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack