๐ท๐บ
DZBOT
2026-08-24 09:44:43
(11 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
craudiovizai
2026-08-20 06:30:07
(4 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
MatCat
2026-08-17 06:05:09
(1 week ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐ง๐ช
madeit
2026-08-13 05:57:40
(1 week ago)
Web App Attack
๐บ๐ธ
craudiovizai
2026-08-12 00:30:51
(1 week ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
Erpelstolz
2026-08-05 07:40:23
(2 weeks ago)
external host: 162.158.94.11 - - [05/Aug/2026:09:40:22 +0200] "GET /wp-admin/install.php?step=1 HTTP ...
show more
external host: 162.158.94.11 - - [05/Aug/2026:09:40:22 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 325 "-" "http://erpelstolz.com/wp-admin/install.php?step=1" CF-Ray:a26427407f141b93-FRA CF-IP:-
show less
Web App Attack
๐ท๐บ
DZBOT
2026-07-18 10:17:54
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
OptimusGO
2026-07-02 12:39:27
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-02 13:39:27 UTC
Log evidence:
162.158.94.11 - - [02/Jul/2026:13:39:25 +0100] "GET /.env HTTP/1.1" 404 181 "http://optimusrentals.co.za/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36"
07/02/2026-13:39:25.138541 [wDrop] [**] [1:1000110:2] SECURITY CRITICAL: .env File Access Attempt - INSTANT BAN [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 162.158.94.11:13755 -> 185.127.18.66:80
07/02/2026-13:39:25.138541 [wDrop] [**] [1:7000911:2] FINSERV CRITICAL: Environment File Access [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 162.158.94.11:13755 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 11:35:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 07:35:06.266211 2026] [security2:error] [pid 20608:tid 20608] [client 162.158.94.11:12420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greenlight.us"] [uri "/.git/config"] [unique_id "aiFi6mn-9a6nIhxCzwGQHgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 14:57:52
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:57:47.628061 2026] [security2:error] [pid 32433:tid 32433] [client 162.158.94.11:14074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lyounglaw.com"] [uri "/.git/config"] [unique_id "ah7va3-RwgiuTnO2PabqawAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 08:06:55
(2 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 03:27:15
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 23:27:12.641595 2026] [security2:error] [pid 10856:tid 10867] [client 162.158.94.11:11793] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uoexpanse.com"] [uri "/.git/config"] [unique_id "ah5NkO-mlQbolfWeHhLGSwAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 09:52:33
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 05:52:27.825368 2026] [security2:error] [pid 29372:tid 29372] [client 162.158.94.11:11924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "switkoprofiri.org.gabver.com"] [uri "/.git/config"] [unique_id "ahgQW-sppYPCzDCB_ulAlwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 04:15:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 00:15:49.496289 2026] [security2:error] [pid 26134:tid 26134] [client 162.158.94.11:13475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sawmat.com"] [uri "/.env.backup"] [unique_id "agfvdcJW5mGMG_H-ObZ6oQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:30:32
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:30:23.337984 2026] [security2:error] [pid 32036:tid 32036] [client 162.158.94.11:9909] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manvsfoodlocations.com"] [uri "/.env.development"] [unique_id "agbLj5Os8rPogub79E8M-QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack