๐ฌ๐ง
ISPLtd
2026-07-21 04:32:29
(2 months ago)
162.158.95.254 - - [21/Jul/2026:01:32:29 -0300] "GET /wp-PII/install.php?step=1
162.158.95.254 - - [ ...
show more
162.158.95.254 - - [21/Jul/2026:01:32:29 -0300] "GET /wp-PII/install.php?step=1
162.158.95.254 - - [21/Jul/2026:01:32:29 -0300] "GET /wp-PII/install.php?step=1
...
show less
Hacking
Web App Attack
๐ฌ๐ง
ISPLtd
2026-07-20 06:06:14
(2 months ago)
162.158.95.254 - - [20/Jul/2026:03:06:13 -0300] "GET /wp-PII/install.php?step=1
162.158.95.254 - - [ ...
show more
162.158.95.254 - - [20/Jul/2026:03:06:13 -0300] "GET /wp-PII/install.php?step=1
162.158.95.254 - - [20/Jul/2026:03:06:13 -0300] "GET /wp-PII/install.php?step=1
...
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-06 22:03:56
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 10:05:47
(3 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
Anonymous
2026-05-16 00:42:05
(4 months ago)
162.158.95.254 - - [16/May/2026:00:42:03 +0000] "GET /backup.sql HTTP/1.1" 302 645 "https://www.goog ...
show more
162.158.95.254 - - [16/May/2026:00:42:03 +0000] "GET /backup.sql HTTP/1.1" 302 645 "https://www.google.com/search?q=gassycat.co.uk" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Shaik Sai Meera
2026-05-13 02:45:06
(4 months ago)
Web Shell Access Attempt
Web App Attack
Brute-Force
Open Proxy
๐บ๐ธ
TPI-Abuse
2026-05-12 01:30:22
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 21:30:19.488702 2026] [security2:error] [pid 27900:tid 27900] [client 162.158.95.254:12224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frenosilent.com.ar.misterflores.com"] [uri "/.git/config"] [unique_id "agKCqwpA6cl9IZCnxWBxUwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 02:26:25
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 22:26:15.023320 2026] [security2:error] [pid 23075:tid 23075] [client 162.158.95.254:10740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.loveoflearning.com"] [uri "/.env.development"] [unique_id "agE-R0eo3iIGj1ZtdAtFAgAAAAk"], referer: https://www.google.com/search?q=webdisk.loveoflearning.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 19:00:21
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 15:00:12.601956 2026] [security2:error] [pid 19302:tid 19302] [client 162.158.95.254:10589] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pawlewicz.org"] [uri "/.env"] [unique_id "agDVvJgIgCX94o_NbMnwwAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 07:54:35
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 03:54:27.428918 2026] [security2:error] [pid 416:tid 416] [client 162.158.95.254:13038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.sawtoothstudios.com"] [uri "/.git/config"] [unique_id "afMKs32oQzrg469eorwlsQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-11 13:02:13
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 09:02:10.062607 2026] [security2:error] [pid 2658053:tid 2658053] [client 162.158.95.254:9511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lockyers.com"] [uri "/.git/config"] [unique_id "adpGUu-9_0llRQg5s2gHkgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-10 00:13:54
(5 months ago)
[Fri Apr 10 02:13:53.244994 2026] [authz_core:error] [pid 32530] [client 162.158.95.254:11465] AH016 ...
show more
[Fri Apr 10 02:13:53.244994 2026] [authz_core:error] [pid 32530] [client 162.158.95.254:11465] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Apr 10 02:13:53.475010 2026] [authz_core:error] [pid 32530] [client 162.158.95.254:11465] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Apr 10 02:13:53.703622 2026] [authz_core:error] [pid 32530] [client 162.158.95.254:11465] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 13:37:11
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 09:37:04.993082 2026] [security2:error] [pid 2943252:tid 2943252] [client 162.158.95.254:14055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.electric-meat-grinder.com"] [uri "/.env.production"] [unique_id "adZaAMCUoN02rs3eIlC0pgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 09:06:15
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.95.254 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 05:05:57.975600 2026] [security2:error] [pid 2903126:tid 2903126] [client 162.158.95.254:9719] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thebradleyclinic.com"] [uri "/.git/logs/HEAD"] [unique_id "adYadQViIIQc8Ems-FRfgQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-07 19:05:34
(5 months ago)
Scanning/Probing (28)
Brute-Force
Web App Attack