๐ง๐ช
madeit
2026-08-27 19:31:37
(3 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-12 22:42:26
(1 month ago)
Web App Attack
๐ซ๐ท
UnixPrime
2026-07-27 21:27:57
(1 month ago)
162.158.95.166 - - [27/Jul/2026:23:27:56 +0200] "GET /.env.save HTTP/1.1" 404 9 "-" "TLM-Audit-Scann ...
show more
162.158.95.166 - - [27/Jul/2026:23:27:56 +0200] "GET /.env.save HTTP/1.1" 404 9 "-" "TLM-Audit-Scanner/1.0"
162.158.95.166 - - [27/Jul/2026:23:27:56 +0200] "GET /.git/config.bak HTTP/1.1" 404 9 "-" "TLM-Audit-Scanner/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-05-17 10:42:50
(4 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 00:43:10
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 20:42:58.181911 2026] [security2:error] [pid 2364:tid 2364] [client 162.158.95.166:10426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cabwebs.com"] [uri "/.git/config"] [unique_id "afvgEiufgcmx3LJeq-61HwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
eyesilyurt
2026-05-05 02:12:41
(4 months ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-05-03 17:10:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 13:10:27.371756 2026] [security2:error] [pid 19791:tid 19791] [client 162.158.95.166:9612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alpha-hk.com"] [uri "/.git/config"] [unique_id "afeBgx9FnRaroXheMqCcdgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 18:44:35
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 14:40:33.969904 2026] [security2:error] [pid 2006528:tid 2006528] [client 162.158.95.166:14168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "citystreetsalon.com"] [uri "/.env.backup"] [unique_id "aekWIcH8xvooMsGxLhECXQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-16 11:32:13
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 07:32:05.036462 2026] [security2:error] [pid 2098709:tid 2098709] [client 162.158.95.166:10067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ncparanormalresearch.andrsn.com"] [uri "/.git/config"] [unique_id "aeDItS6wtKrKP7_PpNmWxQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-13 16:31:06
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 12:31:01.512776 2026] [security2:error] [pid 982911:tid 982911] [client 162.158.95.166:14031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "universtech.softwarezz.net"] [uri "/.env.test"] [unique_id "ad0aRR4NKmJQ3iS1GKbo3wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
netfactotum
2026-04-09 03:53:31
(5 months ago)
Hacking
Web App Attack
Anonymous
2026-04-08 15:34:48
(5 months ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 03:10:21
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 23:10:15.140832 2026] [security2:error] [pid 1373449:tid 1373449] [client 162.158.95.166:9901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.duhcathlon.com"] [uri "/.git/HEAD"] [unique_id "adR1lzW0wep1h12V6luOrwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-06 12:05:06
(5 months ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ซ๐ท
masterguru
2026-04-06 10:59:34
(5 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-196)
Hacking