🇺🇸
TPI-Abuse
2026-09-15 13:45:11
(18 minutes ago)
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:45:03.196974 2026] [security2:error] [pid 6261:tid 6261] [client 169.58.43.159:42470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thejuniverse.org"] [uri "/.git/config"] [unique_id "aqlL3_TC2nS9dmxDQ8XJhAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-15 13:35:10
(28 minutes ago)
Probing websites for vulnerabilities
Web App Attack
🇫🇷
arsonist
2026-09-15 13:32:46
(31 minutes ago)
[fail2ban]
2026-09-15T13:32:46.195196+00:00 arson caddy[1890453]: {"level":"info","ts":1789479166.19 ...
show more
[fail2ban]
2026-09-15T13:32:46.195196+00:00 arson caddy[1890453]: {"level":"info","ts":1789479166.1951602,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"169.58.43.159","remote_port":"42506","client_ip":"169.58.43.159","proto":"HTTP/1.1","method":"GET","host":"autodiscover.nyoemii.dev","uri":"/.git/config","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"autodiscover.nyoemii.dev","ech":false}},"bytes_read":0,"user_id":"","duration":0.000028203,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-15 13:19:28
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:19:22.691934 2026] [security2:error] [pid 22140:tid 22140] [client 169.58.43.159:35368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.scotts.net"] [uri "/.git/config"] [unique_id "aqlF2kLAjShaiVz0mdgevQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 12:13:27
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 08:13:23.243650 2026] [security2:error] [pid 19901:tid 19901] [client 169.58.43.159:45544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jeffhenry.net"] [uri "/.git/config"] [unique_id "aqk2Y4PrbyRqNZ9VMGfB2AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 11:12:15
(2 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
Lee Daniel
2026-09-15 10:03:03
(4 hours ago)
169.58.43.159 - - [15/Sep/2026:06:03:02 -0400] "GET /.env HTTP/1.1" 403 6291 "-" "Mozilla/5.0 (Windo ...
show more
169.58.43.159 - - [15/Sep/2026:06:03:02 -0400] "GET /.env HTTP/1.1" 403 6291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 09:30:12
(4 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-15 08:30:54
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:30:51.184053 2026] [security2:error] [pid 25102:tid 25149] [client 169.58.43.159:47088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.seguroslugo.net"] [uri "/.env.old"] [unique_id "aqkCO9wQ3R5yeqgOtFXwvAAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 07:31:36
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:31:27.910099 2026] [security2:error] [pid 2582:tid 2582] [client 169.58.43.159:41632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saynotoofland.org"] [uri "/wp-config.php.bak"] [unique_id "aqj0T8V2BDvR-JjnhAJ2pgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 07:18:02
(6 hours ago)
apache vulnerability scan
Web App Attack
Anonymous
2026-09-15 06:42:03
(7 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.swp HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 05:56:39
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 169.58.43.159 (vmi3451813.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 01:56:35.065115 2026] [security2:error] [pid 30954:tid 30954] [client 169.58.43.159:52590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.antiradares.net"] [uri "/.env.txt"] [unique_id "aqjeE2m58rcXbfrMS9GNTgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-15 05:46:17
(8 hours ago)
169.58.43.159 - - [15/Sep/2026:08:46:16 +0300] "GET /.env.txt HTTP/1.1" 200 858 "-" "Mozilla/5.0 (Wi ...
show more
169.58.43.159 - - [15/Sep/2026:08:46:16 +0300] "GET /.env.txt HTTP/1.1" 200 858 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
169.58.43.159 - - [15/Sep/2026:08:46:16 +0300] "GET /.git/config HTTP/1.1" 200 858 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇩🇪
4server
2026-09-15 05:44:15
(8 hours ago)
[TueSep1507:44:09.9429152026][security2:error][pid2828280:tid2828408][client169.58.43.159:0]ModSecur ...
show more
[TueSep1507:44:09.9429152026][security2:error][pid2828280:tid2828408][client169.58.43.159:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autoconfig.your-team.ch\"][uri\"/.env.txt\"][unique_id\"aqjbKfoh6BH4qqVnmtbDMQAAAQo\"]
show less
Port Scan
Brute-Force
Web App Attack