๐จ๐ญ
backslash
2025-06-30 03:22:16
(1 year ago)
Bad Web Bot
๐จ๐ณ
ThreatBook.io
2025-06-27 23:36:38
(1 year ago)
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/20.58.128.169
2025-06- ...
show more
ThreatBook Intelligence: Zombie,Spam more details on https://threatbook.io/ip/20.58.128.169
2025-06-27 17:33:41 /.git/config
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-27 11:10:43
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 27 07:10:40.151069 2025] [security2:error] [pid 2595563:tid 2595563] [client 20.58.128.169:53702] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wea-inc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wea-inc.com"] [uri "/db_dump.sql"] [unique_id "aF58MG1LTK_ESYhJSg6RwwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-27 07:16:18
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 27 03:16:12.375935 2025] [security2:error] [pid 1972603:tid 1972620] [client 20.58.128.169:37466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "losersoftheyear.net"] [uri "/web.config"] [unique_id "aF5FPMXED0YiTJewHSZKQgAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
Xpektor
2025-06-27 05:14:00
(1 year ago)
Scanning for vulnerabilities
Hacking
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2025-06-27 04:10:11
(1 year ago)
Scanning for Laravel vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-26 09:46:42
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 26 05:46:38.704226 2025] [security2:error] [pid 1769228:tid 1769228] [client 20.58.128.169:60752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.williamcline.com"] [uri "/web.config"] [unique_id "aF0W_jy9LuhDM53TrypAlgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-26 02:05:30
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 22:05:25.313019 2025] [security2:error] [pid 766725:tid 766747] [client 20.58.128.169:34902] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.planillas.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.planillas.net"] [uri "/dump.sql"] [unique_id "aFyq5ZC1lLaZ0IUGlRf8vwAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-25 20:03:18
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 16:03:14.296023 2025] [security2:error] [pid 598380:tid 598380] [client 20.58.128.169:32908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jefflowenstein.com"] [uri "/.env"] [unique_id "aFxWAjZ4kNpNJdQsFi9TNgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-25 16:19:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 12:19:45.839260 2025] [security2:error] [pid 766525:tid 766525] [client 20.58.128.169:50054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rodandreelpiercam.com"] [uri "/web.config"] [unique_id "aFwhoZ5QH1KsizP4jJrGHwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
weblite
2025-06-25 10:03:12
(1 year ago)
WP_EXPLOIT_PROBE
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-25 07:10:16
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 03:10:11.987058 2025] [security2:error] [pid 3474214:tid 3474214] [client 20.58.128.169:44294] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tedmccachren.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tedmccachren.com"] [uri "/labs/indexlabs.html/db_dump.sql"] [unique_id "aFug02gY5N5FbO76Opwe4QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-06-25 03:05:38
(1 year ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-24 16:12:09
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.58.128.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 24 12:12:02.750808 2025] [security2:error] [pid 2572966:tid 2572966] [client 20.58.128.169:34890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pamcogrp.com"] [uri "/.env"] [unique_id "aFrOUlHA9xw4jkwoEufhXwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2025-06-24 14:10:51
(1 year ago)
Probing for application vulnerabilities
Brute-Force
Web App Attack