π¨π³
ThreatBook.io
2025-06-27 23:35:52
(1 year ago)
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/13.75.130.159
2025-06-2 ...
show more
ThreatBook Intelligence: Zombie,IDC more details on https://threatbook.io/ip/13.75.130.159
2025-06-27 17:32:41 /.env
2025-06-27 17:33:51 /.github/workflows/ci.yml
show less
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-27 07:14:43
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 27 03:14:37.712162 2025] [security2:error] [pid 1972603:tid 1972618] [client 13.75.130.159:42218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "losersoftheyear.net"] [uri "/.env.local"] [unique_id "aF5E3cXED0YiTJewHSZKEQAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
Xpektor
2025-06-27 05:15:00
(1 year ago)
Scanning for vulnerabilities
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-26 21:17:08
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 26 17:17:05.061689 2025] [security2:error] [pid 2065107:tid 2065107] [client 13.75.130.159:34852] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||namefinder.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "namefinder.com"] [uri "/db_dump.sql"] [unique_id "aF240Q0ds2FJ5QLUjQUqawAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Mangelot Hosting
2025-06-26 17:16:12
(1 year ago)
(bad_user_agent) srv104 Bad User-Agent 13.75.130.159 (AU/Australia/-): 10 in the last 3600 secs; Por ...
show more
(bad_user_agent) srv104 Bad User-Agent 13.75.130.159 (AU/Australia/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
π³π±
Mangelot Hosting
2025-06-26 07:52:14
(1 year ago)
(bad_user_agent) srv101 Bad User-Agent 13.75.130.159 (AU/Australia/-): 10 in the last 3600 secs; Por ...
show more
(bad_user_agent) srv101 Bad User-Agent 13.75.130.159 (AU/Australia/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-26 03:10:49
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 23:10:45.018470 2025] [security2:error] [pid 993351:tid 993351] [client 13.75.130.159:42772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wallpaperpro.com"] [uri "/web.config"] [unique_id "aFy6NU98tusYRmAe-9BG6gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-26 00:48:12
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 20:48:05.802901 2025] [security2:error] [pid 794384:tid 794384] [client 13.75.130.159:53486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "561glass.com"] [uri "/.env.local"] [unique_id "aFyYxQ_4ioSfdhIhjpABNAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-25 20:06:59
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 16:06:54.231301 2025] [security2:error] [pid 604106:tid 604106] [client 13.75.130.159:59926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jefflowenstein.com"] [uri "/.git/config"] [unique_id "aFxW3mY5whtaOTjaC6M9RwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-25 18:34:26
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 14:34:21.522082 2025] [security2:error] [pid 460266:tid 460266] [client 13.75.130.159:56794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nbcnewsradio.com"] [uri "/.env.local"] [unique_id "aFxBLZ5OUSFO2PGierFoBQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-25 15:09:20
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 13.75.130.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 11:09:15.460948 2025] [security2:error] [pid 525808:tid 525808] [client 13.75.130.159:42412] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.natickvillagerentals.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.natickvillagerentals.com"] [uri "/dump.sql"] [unique_id "aFwRG_QEa_tV_cFtCmY7_gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2025-06-24 22:05:12
(1 year ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
π³π±
BlueWire Hosting
2025-06-24 14:10:51
(1 year ago)
Probing for application vulnerabilities
Brute-Force
Web App Attack
π¦πΉ
RenΓ© Hickersberger
2025-06-24 12:48:12
(1 year ago)
[2025-06-24T12:45:35Z] Malicious request to /.env.local
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
mawan
2025-06-24 10:33:41
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack