π§π·
maviei
2026-06-18 09:14:36
(2 days ago)
2026-06-18T06:14:34.153393-03:00 srv1251771 kernel: [1540902.879357] [UFW BLOCK] IN=eth0 OUT= MAC=40 ...
show more
2026-06-18T06:14:34.153393-03:00 srv1251771 kernel: [1540902.879357] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.94.176 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=45097 DF PROTO=TCP SPT=12547 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-18T06:14:35.159591-03:00 srv1251771 kernel: [1540903.886016] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.94.176 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=45098 DF PROTO=TCP SPT=12547 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-18T06:14:36.184458-03:00 srv1251771 kernel: [1540904.911199] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.94.176 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=45099 DF PROTO=TCP SPT=12547 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
πΊπΈ
WellSpring
2026-05-14 02:49:20
(1 month ago)
wordpress scan on 585.today/wp-admin/install.php β WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-13 11:37:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 07:37:06.027856 2026] [security2:error] [pid 20294:tid 20294] [client 162.158.94.176:12079] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.luxebikinis.com"] [uri "/sftp-config.json"] [unique_id "agRiYsIlgaWCZOkfFEw-cAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-08 14:05:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 10:05:09.127805 2026] [security2:error] [pid 5178:tid 5178] [client 162.158.94.176:10092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mitchellamazing.com"] [uri "/.git/config"] [unique_id "af3tlcxjoiBiI0wH25Js4gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-30 20:10:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 16:10:48.647688 2026] [security2:error] [pid 874:tid 874] [client 162.158.94.176:12740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.numbulary.com"] [uri "/.git/config"] [unique_id "afO3SEVKdVY66m38zpuYeQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-30 08:42:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 04:42:01.451909 2026] [security2:error] [pid 10988:tid 10988] [client 162.158.94.176:10906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lightningroddesigns.com"] [uri "/.git/config"] [unique_id "afMV2YEp-3N4LhnNBg5ggwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-26 07:49:13
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 03:49:09.134165 2026] [security2:error] [pid 30628:tid 30628] [client 162.158.94.176:14259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "patrickconklin.com"] [uri "/.git/config"] [unique_id "ae3Ddc6ayVJHxidHzMxuNAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-13 21:23:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 17:23:24.474824 2026] [security2:error] [pid 682678:tid 682678] [client 162.158.94.176:10905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mvseasea.com"] [uri "/.git/config"] [unique_id "ad1ezEa7Bf56AsTJZ14fogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-13 07:10:59
(2 months ago)
162.158.94.176 - - [13/Apr/2026:07:10:58 +0000] "GET /.env.production.local HTTP/1.1" 404 6402 "-" " ...
show more
162.158.94.176 - - [13/Apr/2026:07:10:58 +0000] "GET /.env.production.local HTTP/1.1" 404 6402 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
wimaxnz
2026-04-11 00:20:16
(2 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
Anonymous
2026-04-08 18:04:37
(2 months ago)
Aggressive web scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 18:25:47
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 14:25:41.400354 2026] [security2:error] [pid 569941:tid 569973] [client 162.158.94.176:10196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cocoonprojects.com"] [uri "/.git/config"] [unique_id "adP6pZqugXf8R0qx_0et2AAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-04-06 09:48:24
(2 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
mnsf
2026-04-06 07:05:19
(2 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 03:39:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 23:39:15.323907 2026] [security2:error] [pid 32281:tid 32281] [client 162.158.94.176:10594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powderriverinc.com"] [uri "/.git/refs/heads/master"] [unique_id "adMq4-veZHkrN9bYYgBgSgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack