๐บ๐ธ
TPI-Abuse
2026-09-25 11:57:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 82.165.86.143 (infongq-eu66.clienthosting.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.86.143 (infongq-eu66.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 07:57:39.240080 2026] [security2:error] [pid 19878:tid 19878] [client 82.165.86.143:42064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biketurtlehill.com"] [uri "/.env"] [unique_id "arZhsxRWPyVtuVNuG4mu5wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-25 07:15:28
(1 day ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.env | 2026-09-25 07:15 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
todix
2026-09-25 05:32:39
(1 day ago)
Web App Attack Exploid from 82.165.86.143
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:39:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 82.165.86.143 (infongq-eu66.clienthosting.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.86.143 (infongq-eu66.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:38:59.113552 2026] [security2:error] [pid 12199:tid 12199] [client 82.165.86.143:44792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.doctoredwinalvarez.com"] [uri "/wp-config.php.bak"] [unique_id "arL1cyq74FwJ04Sias_OCAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:39:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 82.165.86.143 (infongq-eu66.clienthosting.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.86.143 (infongq-eu66.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:39:53.714203 2026] [security2:error] [pid 20624:tid 20624] [client 82.165.86.143:49034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hi-modulus.com"] [uri "/wp-config.php.bak"] [unique_id "arLZiTUZ-jY7ash4KwrmDAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-22 18:00:39
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 11:56:41
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 82.165.86.143 (infongq-eu66.clienthosting.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.86.143 (infongq-eu66.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:56:34.106415 2026] [security2:error] [pid 5049:tid 5049] [client 82.165.86.143:55420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "meshbagsandmore.com"] [uri "/wp-config.php.bak"] [unique_id "arJs8rY9ObhqHnH8MuIAxwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 04:43:29
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 82.165.86.143 (infongq-eu66.clienthosting.eu): ...
show more
(mod_security) mod_security (id:210492) triggered by 82.165.86.143 (infongq-eu66.clienthosting.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:43:21.276096 2026] [security2:error] [pid 4490:tid 4490] [client 82.165.86.143:39564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mikewakimphotos.com"] [uri "/.env"] [unique_id "arIHafXmd_KYnB64gDT44wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ParaBug
2025-08-15 08:21:58
(1 year ago)
82.165.86.143 - - [15/Aug/2025:10:21:58 +0200] "HEAD /docs.zip HTTP/1.1" 301 180 "-" "-"
...
Phishing
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-08-14 06:54:55
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐ฉ๐ช
todix
2025-07-31 03:55:07
(1 year ago)
WebAttack or semilar from 82.165.86.143
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2025-07-24 13:31:55
(1 year ago)
82.165.86.143 - - [24/Jul/2025:16:31:54 +0300] "HEAD /wordpress.zip HTTP/1.1" 301 0 "-" "-"
...
Hacking
Web App Attack
๐ฌ๐ง
[email protected]
2025-07-23 20:18:58
(1 year ago)
ringtonsreps.academy:443 82.165.86.143 - - [23/Jul/2025:20:18:57 +0000] "HEAD /old.zip HTTP/1.1" 404 ...
show more
ringtonsreps.academy:443 82.165.86.143 - - [23/Jul/2025:20:18:57 +0000] "HEAD /old.zip HTTP/1.1" 404 4051 "-" "-"
ringtonsreps.academy:443 82.165.86.143 - - [23/Jul/2025:20:18:57 +0000] "HEAD /public.zip HTTP/1.1" 404 4051 "-" "-"
ringtonsreps.academy:443 82.165.86.143 - - [23/Jul/2025:20:18:57 +0000] "HEAD /wp.zip HTTP/1.1" 404 4051 "-" "-"
...
show less
Web App Attack
๐ฉ๐ช
LRob
2025-07-19 18:00:21
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
Anonymous
2025-07-18 12:49:45
(1 year ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-config.php1
Web App Attack