π§π·
maviei
2026-06-11 11:45:09
(1 week ago)
2026-06-11T08:45:06.784455-03:00 srv1251771 kernel: [945137.088455] [UFW BLOCK] IN=eth0 OUT= MAC=40: ...
show more
2026-06-11T08:45:06.784455-03:00 srv1251771 kernel: [945137.088455] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.95.199 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=23975 DF PROTO=TCP SPT=11586 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-11T08:45:07.834674-03:00 srv1251771 kernel: [945138.139638] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.95.199 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=23976 DF PROTO=TCP SPT=11586 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-11T08:45:08.859469-03:00 srv1251771 kernel: [945139.163996] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=162.158.95.199 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=23977 DF PROTO=TCP SPT=11586 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
π·πΊ
DZBOT
2026-06-08 23:26:53
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-06 00:06:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 20:06:03.289947 2026] [security2:error] [pid 7158:tid 7158] [client 162.158.95.199:12256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffmasonmusic.com"] [uri "/.git/config"] [unique_id "aiNka4zGcLywaiFwDN3SjgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-03 01:41:20
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 21:41:17.519422 2026] [security2:error] [pid 30245:tid 30245] [client 162.158.95.199:14140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biketurtlehill.com"] [uri "/.git/config"] [unique_id "ah-GPTfA1gTPafb6euFlvAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 13:26:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 09:25:54.248226 2026] [security2:error] [pid 9762:tid 9762] [client 162.158.95.199:13067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentuckianacordcutters.com"] [uri "/.git/config"] [unique_id "ah7Z4sAdA86GVvVbk9SuNAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-06-02 08:06:49
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-30 15:02:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 11:01:59.892386 2026] [security2:error] [pid 5428:tid 5454] [client 162.158.95.199:13954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.legalreporting.com"] [uri "/.git/config"] [unique_id "afNu57gFwf2Zs7I1pN0z_QAAAZQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-25 03:59:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 24 23:59:17.999861 2026] [security2:error] [pid 16580:tid 16580] [client 162.158.95.199:9664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "djemjaybeats.com"] [uri "/.git/config"] [unique_id "aew8Fddm4abrv12xW-9rbQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-13 21:07:34
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 17:07:27.738221 2026] [security2:error] [pid 2937632:tid 2937632] [client 162.158.95.199:13081] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.xtremeautodetailing.com"] [uri "/.git/config"] [unique_id "ad1bDy4N0sSskx3Kiy9KqAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-04-08 03:05:48
(2 months ago)
Scanning/Probing (18)
Brute-Force
Web App Attack
π«π·
masterguru
2026-04-07 16:30:16
(2 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:Cf-Worker. (5025-193)
Hacking
πΊπΈ
TPI-Abuse
2026-04-04 20:14:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 16:13:59.203120 2026] [security2:error] [pid 1624:tid 1624] [client 162.158.95.199:10604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jbaybru.jbaydeliveries.com"] [uri "/.git/HEAD"] [unique_id "adFxBzmo9TPsOQ12PDI22AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Mangelot Hosting
2026-04-04 05:58:34
(2 months ago)
(modsecurity) srv102 ModSecurity 162.158.95.199 (DE/Germany/-): 10 in the last 3600 secs; Ports: *; ...
show more
(modsecurity) srv102 ModSecurity 162.158.95.199 (DE/Germany/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
π©πͺ
FeG Deutschland
2026-04-04 05:30:24
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
mnsf
2026-04-04 05:05:26
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack