๐ซ๐ฎ
Erpelstolz
2026-08-31 01:12:53
(2 days ago)
external host: 172.71.148.158 - - [31/Aug/2026:03:12:52 +0200] "GET /wp-admin/install.php?step=1 HTT ...
show more
external host: 172.71.148.158 - - [31/Aug/2026:03:12:52 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 325 "-" "http://erpelstolz.com/wp-admin/install.php?step=1" CF-Ray:a3382b5dbcbfdc8a-FRA CF-IP:-
show less
Web App Attack
๐ง๐ช
madeit
2026-08-27 19:32:06
(5 days ago)
Web App Attack
๐ท๐บ
DZBOT
2026-08-27 01:53:02
(6 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
4server
2026-08-22 17:04:51
(1 week ago)
[SatAug2219:04:44.0592072026][security2:error][pid2727903:tid2728041][client172.71.148.158:0]ModSecu ...
show more
[SatAug2219:04:44.0592072026][security2:error][pid2727903:tid2728041][client172.71.148.158:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:user-agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"cpcontacts.royalhosting.ch\"][uri\"/.git/config\"][unique_id\"aonWrA_A6oFh656Z_yRV3QAAARg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ง๐ช
madeit
2026-08-06 11:03:48
(3 weeks ago)
Web App Attack
๐ท๐บ
DZBOT
2026-07-31 00:42:52
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ท๐บ
DZBOT
2026-07-17 19:20:22
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 11:56:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 07:56:55.520227 2026] [security2:error] [pid 19687:tid 19687] [client 172.71.148.158:12524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pomonavalleyptg.net"] [uri "/.git/config"] [unique_id "ald1h4C2cY3yI7xPWqncbwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Erpelstolz
2026-06-27 05:26:46
(2 months ago)
external host: 172.71.148.158 - - [27/Jun/2026:07:26:45 +0200] "GET /wp-admin/install.php?step=1 HTT ...
show more
external host: 172.71.148.158 - - [27/Jun/2026:07:26:45 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 301 325 "-" "http://erpelstolz.com/wp-admin/install.php?step=1" CF-Ray:a12209e5594fdc9c-FRA CF-IP:-
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 10:34:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 06:34:05.478654 2026] [security2:error] [pid 14954:tid 14954] [client 172.71.148.158:10440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "djemjaybeats.com"] [uri "/.git/config"] [unique_id "ajphHaKmv6oi1gcw5LTwNwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
seniorlinuxadmin
2026-06-22 10:47:59
(2 months ago)
172.71.148.158 - - [22/Jun/2026:11:47:53 +0100] "GET /.env.bak HTTP/2.0" 403 158 "https://www.google ...
show more
172.71.148.158 - - [22/Jun/2026:11:47:53 +0100] "GET /.env.bak HTTP/2.0" 403 158 "https://www.google.com/search?q=pelech.net" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Port Scan
Web App Attack
๐ท๐บ
DZBOT
2026-06-19 13:56:33
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ฎ
SamJUK
2026-06-14 02:58:50
(2 months ago)
Multiple WAF Violations
...
Bad Web Bot
Web App Attack
๐ง๐ท
maviei
2026-06-11 11:44:17
(2 months ago)
2026-06-11T08:44:14.813473-03:00 srv1251771 kernel: [945085.118598] [UFW BLOCK] IN=eth0 OUT= MAC=40: ...
show more
2026-06-11T08:44:14.813473-03:00 srv1251771 kernel: [945085.118598] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=172.71.148.158 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=49678 DF PROTO=TCP SPT=9872 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-11T08:44:15.852384-03:00 srv1251771 kernel: [945086.157317] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=172.71.148.158 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=49679 DF PROTO=TCP SPT=9872 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-11T08:44:16.876281-03:00 srv1251771 kernel: [945087.181342] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=172.71.148.158 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=49680 DF PROTO=TCP SPT=9872 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-08 21:01:10
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.158 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 17:01:05.843998 2026] [security2:error] [pid 2318:tid 2318] [client 172.71.148.158:9963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tekrav.kuddlkat.com"] [uri "/.git/config"] [unique_id "aictkVlmCWzq9-JnClsaAQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack