๐ง๐ฌ
Stoyko Stoykov
2026-08-21 22:38:23
(2 days ago)
162.158.95.202 - - [22/Aug/2026:01:38:23 +0300] "GET /wp-admin/network/plugins.php HTTP/1.1" 301 162 ...
show more
162.158.95.202 - - [22/Aug/2026:01:38:23 +0300] "GET /wp-admin/network/plugins.php HTTP/1.1" 301 162 "-" "-"
...
show less
Hacking
Web App Attack
๐ง๐ช
madeit
2026-08-15 16:23:47
(1 week ago)
Web App Attack
๐ฉ๐ช
joharikop
2026-08-06 20:14:12
(2 weeks ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
๐ง๐ช
madeit
2026-08-06 03:00:50
(2 weeks ago)
Web App Attack
๐ท๐บ
DZBOT
2026-08-04 15:22:38
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ท๐บ
DZBOT
2026-07-18 04:47:58
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 21:10:23
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 17:10:19.181406 2026] [security2:error] [pid 26592:tid 26592] [client 162.158.95.202:9927] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "exresearch.com.ieas.org"] [uri "/.git/config"] [unique_id "ajReu1wpJTubGV2H0z0IbwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-16 00:38:06
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
Zydzy
2026-05-02 12:54:24
(3 months ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-exploit.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 09:48:45
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 05:48:41.349632 2026] [security2:error] [pid 5160:tid 5160] [client 162.158.95.202:10492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.transparentforest.com"] [uri "/.git/config"] [unique_id "afMlef5sK8EGnxJrVcbwFAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 09:31:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 05:31:00.292486 2026] [security2:error] [pid 20000:tid 20123] [client 162.158.95.202:13448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ccgparquitectos.com"] [uri "/.git/config"] [unique_id "afMhVLz1dUK0EskyzTHLYwAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 05:33:26
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 01:33:19.998988 2026] [security2:error] [pid 9062:tid 9062] [client 162.158.95.202:9505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jackieherbach.com"] [uri "/.git/config"] [unique_id "afLpn17p3ls_vzdYk6o9NQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-04-21 00:50:22
(4 months ago)
(db_admin_scan) srv102 DB admin scan 162.158.95.202 (DE/Germany/-): 1 in the last 3600 secs; Ports: ...
show more
(db_admin_scan) srv102 DB admin scan 162.158.95.202 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
mnsf
2026-04-04 00:06:35
(4 months ago)
Scanning/Probing (18)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 14:17:13
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 10:17:04.470771 2026] [security2:error] [pid 17305:tid 17305] [client 162.158.95.202:12236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dixiegeek.com"] [uri "/.env.dev"] [unique_id "ac_L4KK7uXcfoMVPS5XAIAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack