๐บ๐ธ
TPI-Abuse
2026-06-16 01:51:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 21:51:28.318646 2026] [security2:error] [pid 12351:tid 12351] [client 162.158.94.233:12660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessemack.com"] [uri "/.git/config"] [unique_id "ajCsIPGqMJ1gUkzBSEiE4AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-25 04:58:34
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฆ๐บ
trentwiles.com
2026-05-17 20:42:00
(1 month ago)
Unauthorized connection attempt detected from IP address 162.158.94.233 to port 80 [SYD]
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-12 03:28:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 23:27:59.307772 2026] [security2:error] [pid 12442:tid 12442] [client 162.158.94.233:11101] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "faithlines.com"] [uri "/.env.local"] [unique_id "agKeP4aQNpUUIGrlbzR9igAAACA"], referer: https://www.google.com/search?q=faithlines.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 19:02:09
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 15:02:02.994617 2026] [security2:error] [pid 21956:tid 21956] [client 162.158.94.233:12689] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||rogerg.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rogerg.com"] [uri "/terraform.tfstate.backup"] [unique_id "agDWKhX6jDCIvGduLEDJ-QAAAAE"], referer: https://www.google.com/search?q=rogerg.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 21:50:53
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 17:50:44.204281 2026] [security2:error] [pid 15648:tid 15648] [client 162.158.94.233:13825] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dshgraphics.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dshgraphics.com"] [uri "/backup.sql"] [unique_id "afJ9NJGxlW1JBcU57smGYAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-04-27 17:39:33
(1 month ago)
wordpress scan on whatcanibuild.org/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security ...
show more
wordpress scan on whatcanibuild.org/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 22:39:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 18:38:57.068505 2026] [security2:error] [pid 828990:tid 828990] [client 162.158.94.233:13957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "urrguide.com.coolingsprings.org"] [uri "/.git/index"] [unique_id "adQ2AdEajA1lb6lldj6uWgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 11:07:23
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 07:07:18.154940 2026] [security2:error] [pid 62376:tid 62376] [client 162.158.94.233:11315] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.coast-consult.com"] [uri "/.env.development.local"] [unique_id "adOT5tN5UET5_IXSMf9_5QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-04-06 10:24:00
(2 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 00:05:19
(2 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐ท๐ด
iulianh
2026-04-04 21:22:39
(2 months ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-04-04 18:17:49
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 14:17:42.723527 2026] [security2:error] [pid 29081:tid 29081] [client 162.158.94.233:13418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tracytappan.net"] [uri "/.env.old"] [unique_id "adFVxmkXRhmv4xxoSNKHLwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-04 06:31:29
(2 months ago)
162.158.94.233 - - [04/Apr/2026:09:31:27 +0300] "GET /server/.env HTTP/1.1" 404 784 "-" "-"
162.158. ...
show more
162.158.94.233 - - [04/Apr/2026:09:31:27 +0300] "GET /server/.env HTTP/1.1" 404 784 "-" "-"
162.158.94.233 - - [04/Apr/2026:09:31:28 +0300] "GET /var/www/.env HTTP/1.1" 404 784 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 04:27:35
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 00:27:25.900494 2026] [security2:error] [pid 15374:tid 15374] [client 162.158.94.233:12470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wtf.hal.dance"] [uri "/.env.local"] [unique_id "adCTLXoibhBMlZ0E30cFFQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack