๐ท๐บ
DZBOT
2026-06-25 22:58:49
(2 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-03 08:10:24
(3 weeks ago)
162.158.95.131 - - [03/Jun/2026:11:10:24 +0300] "POST /xmlrpc.php HTTP/1.1" 404 3349 "-" "Mozilla/5. ...
show more
162.158.95.131 - - [03/Jun/2026:11:10:24 +0300] "POST /xmlrpc.php HTTP/1.1" 404 3349 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-02 07:50:26
(3 weeks ago)
162.158.95.131 - - [02/Jun/2026:10:49:56 +0300] "GET /wp-includes/blocks/ HTTP/1.1" 404 768 "-" "Moz ...
show more
162.158.95.131 - - [02/Jun/2026:10:49:56 +0300] "GET /wp-includes/blocks/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
162.158.95.131 - - [02/Jun/2026:10:50:25 +0300] "GET /wp-includes/pomo/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-01 03:30:07
(3 weeks ago)
162.158.95.131 - - [01/Jun/2026:06:30:05 +0300] "GET /wp-login.php HTTP/1.1" 404 3350 "-" "Mozilla/5 ...
show more
162.158.95.131 - - [01/Jun/2026:06:30:05 +0300] "GET /wp-login.php HTTP/1.1" 404 3350 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
162.158.95.131 - - [01/Jun/2026:06:30:05 +0300] "GET /wp-login.php HTTP/1.1" 404 684 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:119.0) Gecko/20100101 Firefox/119.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 09:03:44
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 05:03:33.604272 2026] [security2:error] [pid 27897:tid 27897] [client 162.158.95.131:9423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.michaelholdawayvideos.info"] [uri "/.env.local"] [unique_id "ahqn5YtPLBtnwZ-e-IFFHgAAABY"], referer: https://www.google.com/search?q=webdisk.michaelholdawayvideos.info
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-24 02:36:43
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-17 22:12:11
(1 month ago)
162.158.95.131 - - [18/May/2026:01:12:10 +0300] "GET /wp-login.php HTTP/1.1" 404 768 "-" "Mozilla/5. ...
show more
162.158.95.131 - - [18/May/2026:01:12:10 +0300] "GET /wp-login.php HTTP/1.1" 404 768 "-" "Mozilla/5.0 (X11; Linux x86_64) Gecko/20100101 Firefox/120.0.1"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-17 13:13:53
(1 month ago)
162.158.95.131 - - [17/May/2026:16:13:51 +0300] "GET /wp-content/backups/ HTTP/1.1" 404 768 "-" "Moz ...
show more
162.158.95.131 - - [17/May/2026:16:13:51 +0300] "GET /wp-content/backups/ HTTP/1.1" 404 768 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-16 16:30:13
(1 month ago)
162.158.95.131 - - [16/May/2026:19:30:06 +0300] "GET /wp-includes/rest-api/ HTTP/1.1" 404 734 "-" "M ...
show more
162.158.95.131 - - [16/May/2026:19:30:06 +0300] "GET /wp-includes/rest-api/ HTTP/1.1" 404 734 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.158.95.131 - - [16/May/2026:19:30:07 +0300] "GET /wp-content/plugins/core-plugin/include.php HTTP/1.1" 404 734 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
strxmpp
2026-05-16 01:17:00
(1 month ago)
162.158.95.131 - - [16/May/2026:03:16:59 +0200] "GET /.git/config HTTP/1.1" 404 4884 "-" "Mozilla/5. ...
show more
162.158.95.131 - - [16/May/2026:03:16:59 +0200] "GET /.git/config HTTP/1.1" 404 4884 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/127.0 Safari/537.36"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-08 01:38:26
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 21:38:21.958469 2026] [security2:error] [pid 27146:tid 27146] [client 162.158.95.131:12576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomasmichaelrussell.com"] [uri "/.git/config"] [unique_id "af0-jVhgIRAjO4iCho1yhwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-02 22:26:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 18:26:05.488402 2026] [security2:error] [pid 16062:tid 16062] [client 162.158.95.131:11433] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rentadeandamioscdmx.com"] [uri "/.git/config"] [unique_id "afZ5_XBB2ERPlSIo04FmnAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 08:15:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 04:15:12.724413 2026] [security2:error] [pid 10378:tid 10378] [client 162.158.95.131:9980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.galengetting.com"] [uri "/.git/config"] [unique_id "afMPkB4qbFhaJzBskyg8SQAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-04-29 23:35:56
(1 month ago)
wordpress scan on freegrounds.org/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security l ...
show more
wordpress scan on freegrounds.org/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-04-26 13:02:23
(2 months ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot