๐ฉ๐ช
FeG Deutschland
2026-06-14 06:07:04
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-11 22:40:54
(3 days ago)
162.158.95.183 - - [12/Jun/2026:01:40:45 +0300] "GET /wp-content/uploads/ HTTP/1.1" 404 768 "-" "Moz ...
show more
162.158.95.183 - - [12/Jun/2026:01:40:45 +0300] "GET /wp-content/uploads/ HTTP/1.1" 404 768 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:121.0) Gecko/20100101 Firefox/121.0"
162.158.95.183 - - [12/Jun/2026:01:40:54 +0300] "GET /wp-admin/includes/ HTTP/1.1" 404 768 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:122.0) Gecko/20100101 Firefox/122.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 03:41:19
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 23:41:14.241063 2026] [security2:error] [pid 7719:tid 7743] [client 162.158.95.183:10260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "review.n2play.net"] [uri "/.git/config"] [unique_id "ahEh2k7d-SN0mD1h1X31DwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 05:52:13
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 01:52:08.503255 2026] [security2:error] [pid 2789:tid 2789] [client 162.158.95.183:10897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.howtolivegreener.com"] [uri "/.env.staging"] [unique_id "aggGCJgGxobwhxtwd9RwxgAAAAE"], referer: https://www.google.com/search?q=webmail.howtolivegreener.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
dispensight
2026-05-16 00:39:22
(4 weeks ago)
Automated WordPress exploit probe via honeydomain. UA: dispensight.buzz. Cloudflare Sweden proxy.
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-05-11 04:19:12
(1 month ago)
162.158.95.183 - - [11/May/2026:07:19:10 +0300] "GET /conf/.env HTTP/1.1" 404 768 "-" "Mozilla/5.0 ( ...
show more
162.158.95.183 - - [11/May/2026:07:19:10 +0300] "GET /conf/.env HTTP/1.1" 404 768 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
162.158.95.183 - - [11/May/2026:07:19:11 +0300] "GET /library/.env HTTP/1.1" 404 767 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 07:14:43
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 03:14:39.219925 2026] [security2:error] [pid 24139:tid 24139] [client 162.158.95.183:9773] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathgen.com"] [uri "/.git/config"] [unique_id "af7e31zZubGLDVAiB_6RSQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-05-08 18:00:28
(1 month ago)
{"level":"info","ts":1778263218.208686,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1778263218.208686,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"162.158.95.183","remote_port":"11554","client_ip":"162.158.95.183","proto":"HTTP/1.1","method":"GET","host":"status.tlh.realty","uri":"/wp-content/","headers":{"Connection":["Keep-Alive"],"Cf-Ray":["9f8a5cf999fc380e-FRA"],"Insecure-Flag":["1"],"Cdn-Loop":["cloudflare; loops=1"],"Cf-Ipcountry":["DE"],"Cf-Visitor":["{\"scheme\":\"http\"}"],"X-Forwarded-For":["91.217.249.215"],"X-Forwarded-Proto":["http"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.79 Safari/537.36"],"Cf-Connecting-Ip":["91.217.249.215"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000058221,"size":0,"status":308,"resp_headers":{"Content-Type":[],"Server":["Caddy"],"Connection":["close"],"Location":["https://status.tlh.realty/wp-content/"]}}
{"level":"info","ts":1778263218.2502842,"logger":"http.log.access.log1",
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 11:20:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 07:20:36.567630 2026] [security2:error] [pid 25725:tid 25725] [client 162.158.95.183:10857] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.indigo17.com"] [uri "/.env.development.local"] [unique_id "afx1hMC0Ly-DiZEwxJlhXgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 17:40:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 13:40:26.088125 2026] [security2:error] [pid 27735:tid 27735] [client 162.158.95.183:10360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "central-wi-coal-sales.com"] [uri "/.git/config"] [unique_id "afeIigVsgH_Zm7OFkBh3-AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 16:51:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 12:51:18.233934 2026] [security2:error] [pid 30846:tid 30882] [client 162.158.95.183:10477] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aaenroll.com"] [uri "/.git/config"] [unique_id "afOIhozWFS_q1Be6POZmRQAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-04-18 02:01:59
(1 month ago)
Failed attempt detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-04-08 05:41:34
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 05:57:20
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 01:57:15.264119 2026] [security2:error] [pid 1561848:tid 1561848] [client 162.158.95.183:11851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hayrun.com"] [uri "/.git/index"] [unique_id "adScu2jidS8_uGTkkyovXgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 21:05:22
(2 months ago)
Scanning/Probing (19)
Brute-Force
Web App Attack