Anonymous
2026-06-14 15:55:02
(2 days ago)
suspicious request in access.log
Web App Attack
πΊπΈ
mnsf
2026-06-14 07:06:53
(3 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-13 10:51:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 162.159.113.40 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.159.113.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 06:51:00.374046 2026] [security2:error] [pid 22030:tid 22054] [client 162.159.113.40:14234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "la.oplconnect.com"] [uri "/.git/config"] [unique_id "ai02FCo4HFzxR-rTCh0hZgAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 01:55:28
(6 days ago)
(caddyscan) Scanner path probe from 162.159.113.40 (NL/The Netherlands/-): 5 in the last 3600 secs; ...
show more
(caddyscan) Scanner path probe from 162.159.113.40 (NL/The Netherlands/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 162.159.113.40 - - [11/Jun/2026:01:55:17 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 162.159.113.40 - - [11/Jun/2026:01:55:17 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 162.159.113.40 - - [11/Jun/2026:01:55:17 +0000] "GET /.env.development HTTP/1.1"
[REDACTED] 200 2627 162.159.113.40 - - [11/Jun/2026:01:55:25 +0000] "GET /.env.local.copy HTTP/1.1"
[REDACTED] 200 2627 162.159.113.40 - - [11/Jun/2026:01:55:25 +0000] "GET /.env.local.backup HTTP/1.1"
show less
Port Scan
π¦π±
router.al
2026-06-10 19:42:15
(6 days ago)
06/10/2026-19:42:14.806646 162.159.113.40 Protocol: 6 GPL WEB_SERVER 403 Forbidden
Port Scan
π·πΊ
DZBOT
2026-06-08 20:12:49
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
π¦π±
router.al
2026-06-03 11:58:40
(2 weeks ago)
06/03/2026-11:58:40.142653 162.159.113.40 Protocol: 6 GPL WEB_SERVER 403 Forbidden
Port Scan
π³π±
homeshowdomain.nl
2026-05-29 22:06:13
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-28.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-05-28 09:56:48
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.159.113.40 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.159.113.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 05:56:34.709093 2026] [security2:error] [pid 7887:tid 7887] [client 162.159.113.40:11532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.alanbeckwith.com"] [uri "/.env.backup"] [unique_id "ahgRUomzEdYQd86ReY8o8QAAAAE"], referer: https://www.google.com/search?q=mail.alanbeckwith.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-28 09:28:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.159.113.40 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.159.113.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 05:27:54.002334 2026] [security2:error] [pid 5592:tid 5592] [client 162.159.113.40:12103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.notearsweb.com"] [uri "/.env.development.local"] [unique_id "ahgKmuhhgrUqt13UpU8YYAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦π±
router.al
2026-05-28 04:30:45
(2 weeks ago)
05/28/2026-04:30:44.604859 162.159.113.40 Protocol: 6 GPL WEB_SERVER 403 Forbidden
Port Scan
Anonymous
2026-05-22 22:01:16
(3 weeks ago)
162.159.113.40 - - [22/May/2026:21:57:12 +0000] "GET /config/ses.php HTTP/2.0" 404 2022 "https://coc ...
show more
162.159.113.40 - - [22/May/2026:21:57:12 +0000] "GET /config/ses.php HTTP/2.0" 404 2022 "https://cocrea.ctieg.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Edg/131.0.0.0" "45.148.10.51"
162.159.113.40 - - [22/May/2026:21:57:50 +0000] "GET /brevo.php HTTP/2.0" 404 2022 "https://cocrea.ctieg.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0" "45.148.10.51"
162.159.113.40 - - [22/May/2026:21:58:10 +0000] "GET /sendinblue.php HTTP/2.0" 404 2020 "https://cocrea.ctieg.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:132.0) Gecko/20100101 Firefox/132.0" "45.148.10.51"
162.159.113.40 - - [22/May/2026:21:59:49 +0000] "GET /lib/sendgrid.php HTTP/2.0" 404 2021 "https://cocrea.ctieg.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "45.148.10.51"
162.159.113.40 - - [22/May/2026:21:59:50 +0000] "GET /sendgrid_config.php HTTP/2.
...
show less
Port Scan
Brute-Force
π¦π±
router.al
2026-05-21 01:31:47
(3 weeks ago)
05/21/2026-01:31:47.308231 162.159.113.40 Protocol: 6 GPL WEB_SERVER 403 Forbidden
Port Scan
π³π±
ParaBug
2026-05-18 02:49:39
(4 weeks ago)
162.159.113.40 - - [18/May/2026:04:49:38 +0200] "GET /wp-admin/install.php?step=1 HTTP/2.0" 404 315 ...
show more
162.159.113.40 - - [18/May/2026:04:49:38 +0200] "GET /wp-admin/install.php?step=1 HTTP/2.0" 404 315 "-" "http://myviven.com/wp-admin/install.php?step=1"
...
show less
Phishing
Brute-Force
Web App Attack
π©πͺ
www.mammazone.it
2026-05-15 16:00:23
(1 month ago)
fabiodirauso.it:80 162.159.113.40 - - [15/May/2026:18:00:20 +0200] "GET /test HTTP/1.1" 200 19816 "- ...
show more
fabiodirauso.it:80 162.159.113.40 - - [15/May/2026:18:00:20 +0200] "GET /test HTTP/1.1" 200 19816 "-" "Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.4) Gecko Netscape/7.1 (ax)"
fabiodirauso.it:80 162.159.113.40 - - [15/May/2026:18:00:21 +0200] "GET /.env.example HTTP/1.1" 200 19833 "-" "Mozilla/5.0 (Windows; U; Win98; en-US; rv:1.4) Gecko Netscape/7.1 (ax)"
...
show less
Hacking