πΊπΈ
TPI-Abuse
2026-06-14 10:07:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:07:49.737379 2026] [security2:error] [pid 749:tid 749] [client 162.158.94.154:9305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ozarktulsa.com"] [uri "/.git/config"] [unique_id "ai59dc0KR5cc_uhPUATAUQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
wimaxnz
2026-05-19 02:09:57
(4 weeks ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
π―π΅
S.O.B.A. Dev.
2026-05-18 22:19:49
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
πΊπΈ
wimaxnz
2026-05-17 03:09:45
(1 month ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
πΊπΈ
TPI-Abuse
2026-04-30 12:39:45
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 08:39:40.048245 2026] [security2:error] [pid 8639:tid 8639] [client 162.158.94.154:11682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jbcllcnet.com"] [uri "/.git/config"] [unique_id "afNNjFjOLWFDnY_wAzPFpQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-30 12:23:53
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 08:23:47.473702 2026] [security2:error] [pid 25938:tid 25938] [client 162.158.94.154:13417] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.izloto.com"] [uri "/.git/config"] [unique_id "afNJ02YvY3i8RWqWW4wZsQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-26 08:36:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 04:36:05.013721 2026] [security2:error] [pid 29615:tid 29615] [client 162.158.94.154:9486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oldworldfineantiques.com"] [uri "/.git/config"] [unique_id "ae3OdaLPIa7QFSvKfzTWbAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-07 06:06:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 02:05:59.295835 2026] [security2:error] [pid 789280:tid 789294] [client 162.158.94.154:11314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.alred.net"] [uri "/.git/index"] [unique_id "adSex_quNE8eOdPA4KcG5wAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 11:39:41
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 07:39:33.547070 2026] [security2:error] [pid 28757:tid 28757] [client 162.158.94.154:12285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kqdemo.com"] [uri "/.env.tmp"] [unique_id "adObdcj6mS9bF5HOMFDZXwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 08:05:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 04:05:07.208841 2026] [security2:error] [pid 3506:tid 3506] [client 162.158.94.154:14172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "recipe.planettony.com"] [uri "/.git/logs/HEAD"] [unique_id "adNpMyAnHvaA7oWWt0cGLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
routerjockey
2026-04-04 22:25:48
(2 months ago)
[sensor1] Observed 40 TCP SYN probes in the past 6 hours [Top ports 443/tcp(24x) 80/tcp(16x)]
Port Scan
π³π±
homeshowdomain.nl
2026-04-04 22:01:31
(2 months ago)
Auto-ban: >3000 req/min op 2026-04-04
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-04-03 06:13:47
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 02:13:43.402603 2026] [security2:error] [pid 32521:tid 32521] [client 162.158.94.154:12147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.leadek.com"] [uri "/.git/config"] [unique_id "ac9alxPAcCGn21BWokfabQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 01:35:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 21:34:59.538197 2026] [security2:error] [pid 18165:tid 18165] [client 162.158.94.154:11488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cultiplant.com.menagri.com"] [uri "/private/.env"] [unique_id "ac8ZQ1SDOBYGEdqcShqAMAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
pm33
2026-04-02 12:10:04
(2 months ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack