๐ฉ๐ช
4server
2026-09-27 10:14:56
(2 days ago)
[SunSep2712:14:51.9993212026][security2:error][pid3503362:tid3503416][client162.158.88.67:0]ModSecur ...
show more
[SunSep2712:14:51.9993212026][security2:error][pid3503362:tid3503416][client162.158.88.67:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"eimeko.ch\"][uri\"/.env.production.local\"][unique_id\"arjsm_D8u5a-9vqD4oPKGwAAABg\"]\,referer:https://www.google.com/search\?q=eimeko.ch
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:51:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:51:20.829901 2026] [security2:error] [pid 27254:tid 27254] [client 162.158.88.67:14090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prosucomexico.com"] [uri "/.env.production.local"] [unique_id "arJruHjVdjIu0GId3z9jywAAACs"], referer: https://www.google.com/search?q=prosucomexico.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-17 01:13:03
(1 week ago)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-08 21:59:12
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
๐ฉ๐ช
Grossmann-Gruppe
2026-08-29 11:05:23
(1 month ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-20 01:10:01
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 21:09:54.774061 2026] [security2:error] [pid 28185:tid 28185] [client 162.158.88.67:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.webuildbeaches.com"] [uri "/src/.env"] [unique_id "aoZT4nGYkhqsvBCmbA2jBwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:18:54
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:18:47.990661 2026] [security2:error] [pid 26031:tid 26031] [client 162.158.88.67:11578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cain2012.cain2016.org"] [uri "/.git/HEAD"] [unique_id "aoLD50PHeEquInnqenheyAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:00:00
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:59:56.691330 2026] [security2:error] [pid 10293:tid 10293] [client 162.158.88.67:10323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.aquascapes.net"] [uri "/.git/HEAD"] [unique_id "aoK_fLBhIFbCaRlXq37l4wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:36:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:36:38.013218 2026] [security2:error] [pid 14030:tid 14030] [client 162.158.88.67:12139] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indiahouseportland.com"] [uri "/.git/HEAD"] [unique_id "aoK6BnZfvTKXtG4LxgSecgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 04:51:01
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:50:57.757417 2026] [security2:error] [pid 10982:tid 10989] [client 162.158.88.67:10581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.busybeerestaurant.com"] [uri "/.git/HEAD"] [unique_id "aoKTMZLIT0EU9t4xY_gFegAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:54:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:54:29.521660 2026] [security2:error] [pid 583:tid 583] [client 162.158.88.67:9679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stlrosesociety.org"] [uri "/.git/config"] [unique_id "aoKF9XevTfadNhC4Fde5PgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:52:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:52:03.649313 2026] [security2:error] [pid 12515:tid 12515] [client 162.158.88.67:12243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tijuanabible.org"] [uri "/.git/HEAD"] [unique_id "aoJ3UziCbvvECzIIM-1bQAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-08-16 01:02:48
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 19:33:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 15:33:31.648305 2026] [security2:error] [pid 907342:tid 907342] [client 162.158.88.67:9717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anus.net"] [uri "/.git/HEAD"] [unique_id "an9ti66OciHQCaMQz6Pq5QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-05-15 00:12:07
(4 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack