๐ช๐ธ
robotstxt
2026-09-24 13:17:29
(45 minutes ago)
162.159.98.4 - - [24/Sep/2026:13:17:21 +0000] "GET /.env HTTP/2.0" 403 2 "-" "Mozilla/5.0 (X11; Linu ...
show more
162.159.98.4 - - [24/Sep/2026:13:17:21 +0000] "GET /.env HTTP/2.0" 403 2 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.142.255.126" edge="162.159.98.4"
162.159.98.4 - - [24/Sep/2026:13:17:22 +0000] "GET /.env.local HTTP/2.0" 403 2 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.142.255.126" edge="162.159.98.4"
162.159.98.4 - - [24/Sep/2026:13:17:22 +0000] "GET /.env.production HTTP/2.0" 403 2 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.142.255.126" edge="162.159.98.4"
162.159.98.4 - - [24/Sep/2026:13:17:22 +0000] "GET /.env.staging HTTP/2.0" 403 2 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.142.255.126" edge="162.159.98.4"
162.159.98.4 - - [24/Sep/2026:13:17:23 +0000] "GET /.env.development HTTP/2.0" 403 2 "-" "Mozilla/5.0 (
...
show less
Web App Attack
Anonymous
2026-09-17 14:30:05
(6 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
homeshowdomain.nl
2026-09-15 22:00:15
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-15
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-09 07:21:10
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.159.98.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.159.98.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:21:07.090936 2026] [security2:error] [pid 24692:tid 24692] [client 162.159.98.4:11444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrbaystreet.com"] [uri "/.env.backup"] [unique_id "aqEI4xWr3DKoM_JIcAqyTQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Axel
2026-08-29 21:23:07
(3 weeks ago)
Blocked by UFW on LAXHH [2009/tcp] | SPT: 11102 | TTL: 54 | LEN: 60 | TOS: 0x00 โข Reported by: githu ...
show more
Blocked by UFW on LAXHH [2009/tcp] | SPT: 11102 | TTL: 54 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
Axel
2026-08-28 20:03:53
(3 weeks ago)
Blocked by UFW on LAXHH [2009/tcp] | SPT: 9262 | TTL: 54 | LEN: 60 | TOS: 0x00 โข Reported by: github ...
show more
Blocked by UFW on LAXHH [2009/tcp] | SPT: 9262 | TTL: 54 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ง๐ช
madeit
2026-08-06 07:47:23
(1 month ago)
Web App Attack
Anonymous
2026-07-25 15:56:07
(1 month ago)
162.159.98.4 - - [25/Jul/2026:15:55:56 +0000] "GET //wp-content/admin.php HTTP/2.0" 404 3605 "-" "-" ...
show more
162.159.98.4 - - [25/Jul/2026:15:55:56 +0000] "GET //wp-content/admin.php HTTP/2.0" 404 3605 "-" "-" "104.208.94.19"
162.159.98.4 - - [25/Jul/2026:15:55:58 +0000] "GET /ms-edit.php HTTP/2.0" 404 3606 "-" "-" "104.208.94.19"
162.159.98.4 - - [25/Jul/2026:15:56:02 +0000] "GET //abcd.php HTTP/2.0" 404 3605 "-" "-" "104.208.94.19"
162.159.98.4 - - [25/Jul/2026:15:56:03 +0000] "GET //a1.php HTTP/2.0" 404 3603 "-" "-" "104.208.94.19"
162.159.98.4 - - [25/Jul/2026:15:56:04 +0000] "GET /wp-includes/Text/Diff/Engine/about.php HTTP/2.0" 404 3625 "-" "-" "104.208.94.19"
162.159.98.4 - - [25/Jul/2026:15:56:04 +0000] "GET //cgi-bin/admin.php HTTP/2.0" 404 3609 "-" "-" "104.208.94.19"
162.159.98.4 - - [25/Jul/2026:15:56:05 +0000] "GET /gettest.php HTTP/2.0" 404 3600 "-" "-" "104.208.94.19"
162.159.98.4 - - [25/Jul/2026:15:56:05 +0000] "GET /simple.php HTTP/2.0" 404 3600 "-" "-" "104.208.94.19"
162.159.98.4 - - [25/Jul/2026:15:56:06 +0000] "GET /xxx.php HTTP/2.0" 404 3604 "-" "-" "104.208.94.19"
162.
...
show less
Port Scan
Brute-Force
Anonymous
2026-06-28 16:41:06
(2 months ago)
162.159.98.4 - - [28/Jun/2026:16:40:56 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php ...
show more
162.159.98.4 - - [28/Jun/2026:16:40:56 +0000] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/2.0" 404 4073 "-" "-" "20.24.211.231"
162.159.98.4 - - [28/Jun/2026:16:41:02 +0000] "GET /Q1.php HTTP/2.0" 404 4051 "-" "-" "20.24.211.231"
162.159.98.4 - - [28/Jun/2026:16:41:02 +0000] "GET /Q3.php HTTP/2.0" 404 4051 "-" "-" "20.24.211.231"
162.159.98.4 - - [28/Jun/2026:16:41:03 +0000] "GET /class.php HTTP/2.0" 404 4049 "-" "-" "20.24.211.231"
162.159.98.4 - - [28/Jun/2026:16:41:03 +0000] "GET /znar.php HTTP/2.0" 404 4050 "-" "-" "20.24.211.231"
162.159.98.4 - - [28/Jun/2026:16:41:03 +0000] "GET /link.php HTTP/2.0" 404 4048 "-" "-" "20.24.211.231"
162.159.98.4 - - [28/Jun/2026:16:41:04 +0000] "GET /xa.php HTTP/2.0" 404 4048 "-" "-" "20.24.211.231"
162.159.98.4 - - [28/Jun/2026:16:41:05 +0000] "GET /class14.php HTTP/2.0" 404 4052 "-" "-" "20.24.211.231"
162.159.98.4 - - [28/Jun/2026:16:41:05 +0000] "GET /ctex1.php HTTP/2.0" 404 4051 "-" "-" "20.24.211.231"
162.159.98.4 - - [28/Jun/
...
show less
Port Scan
Brute-Force
๐ฉ๐ช
london2038.com
2026-06-24 15:58:23
(2 months ago)
Too many failed requests
162.159.98.4 - - [24/Jun/2026:17:58:15 +0200] "GET /signin HTTP/2.0" 404 40 ...
show more
Too many failed requests
162.159.98.4 - - [24/Jun/2026:17:58:15 +0200] "GET /signin HTTP/2.0" 404 40020 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.159.98.4 - - [24/Jun/2026:17:58:15 +0200] "GET /signin HTTP/2.0" 404 40022 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.159.98.4 - - [24/Jun/2026:17:58:15 +0200] "GET /auth/login HTTP/2.0" 404 40021 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.159.98.4 - - [24/Jun/2026:17:58:16 +0200] "GET /auth/login HTTP/2.0" 404 40022 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.159.98.4 - - [24/Jun/2026:17:58:16 +0200] "GET /account/login HTTP/2.0" 404 40021 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537
...
show less
Web Spam
Bad Web Bot
๐ฉ๐ช
acadeova
2026-06-16 22:23:26
(3 months ago)
๐จ Recon detected (nft drop)
SRC=162.159.98.4
Observed=TCP dpt=80 in=enp0s6 ttl=55
Time=recent(journa ...
show more
๐จ Recon detected (nft drop)
SRC=162.159.98.4
Observed=TCP dpt=80 in=enp0s6 ttl=55
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
Anonymous
2026-06-02 03:51:27
(3 months ago)
[Tue Jun 02 05:51:09.716196 2026] [authz_core:error] [pid 15167] [client 162.159.98.4:9971] AH01630: ...
show more
[Tue Jun 02 05:51:09.716196 2026] [authz_core:error] [pid 15167] [client 162.159.98.4:9971] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Jun 02 05:51:09.939358 2026] [authz_core:error] [pid 15167] [client 162.159.98.4:9971] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Jun 02 05:51:27.378781 2026] [authz_core:error] [pid 14134] [client 162.159.98.4:14212] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-05-24 07:40:19
(4 months ago)
[Sun May 24 09:40:17.003001 2026] [authz_core:error] [pid 2905] [client 162.159.98.4:10005] AH01630: ...
show more
[Sun May 24 09:40:17.003001 2026] [authz_core:error] [pid 2905] [client 162.159.98.4:10005] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun May 24 09:40:18.068115 2026] [authz_core:error] [pid 2905] [client 162.159.98.4:10005] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun May 24 09:40:18.537240 2026] [authz_core:error] [pid 2905] [client 162.159.98.4:10005] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-03-28 22:29:52
(5 months ago)
[Sat Mar 28 23:29:51.462476 2026] [authz_core:error] [pid 14323] [client 162.159.98.4:11118] AH01630 ...
show more
[Sat Mar 28 23:29:51.462476 2026] [authz_core:error] [pid 14323] [client 162.159.98.4:11118] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Mar 28 23:29:51.696285 2026] [authz_core:error] [pid 14323] [client 162.159.98.4:11118] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Mar 28 23:29:51.911091 2026] [authz_core:error] [pid 14323] [client 162.159.98.4:11118] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-03-19 22:44:55
(6 months ago)
162.159.98.4 - - [20/Mar/2026:00:44:51 +0200] "GET /wp-content/uploads/index.php HTTP/1.1" 404 357 " ...
show more
162.159.98.4 - - [20/Mar/2026:00:44:51 +0200] "GET /wp-content/uploads/index.php HTTP/1.1" 404 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
162.159.98.4 - - [20/Mar/2026:00:44:55 +0200] "GET /wp-admin/user/index.php HTTP/1.1" 404 357 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack