๐บ๐ธ
TPI-Abuse
2026-10-08 03:06:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:06:33.096898 2026] [security2:error] [pid 32562:tid 32589] [client 181.215.65.37:59211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.178"] [uri "/backend/.env"] [unique_id "ascIufnaYMLvaoPDD5CEDwAAAZc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:52:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:52:21.230192 2026] [security2:error] [pid 9342:tid 9342] [client 181.215.65.37:47971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.223"] [uri "/apps/.env"] [unique_id "asb3VRHxSCesgeVNXGaLhQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:15:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:15:19.388075 2026] [security2:error] [pid 337:tid 337] [client 181.215.65.37:64633] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.181"] [uri "/wp-content/.env"] [unique_id "asbglx_hfnh7M5MJZ4on4wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
lns.bz
2026-10-08 00:00:19
(3 days ago)
.env scanning [DOOZ]
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-07 22:55:22
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 16:37:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 12:37:08.593223 2026] [security2:error] [pid 25778:tid 25778] [client 181.215.65.37:35487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.202"] [uri "/library/.env"] [unique_id "asZ1NBmXvLHyyq14QIaeTQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 14:38:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 10:38:48.126548 2026] [security2:error] [pid 7943:tid 7943] [client 181.215.65.37:51757] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.48"] [uri "/conf/.env"] [unique_id "asZZePd0QfYGGOcFS462MAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 13:59:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 09:59:12.095748 2026] [security2:error] [pid 16994:tid 17013] [client 181.215.65.37:46033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.123"] [uri "/.env"] [unique_id "asZQMPYOhtcBLifxknyeAAAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 11:06:37
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 07:06:32.286397 2026] [security2:error] [pid 2285:tid 2285] [client 181.215.65.37:61341] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.98"] [uri "/wp-admin/.env"] [unique_id "asYnuMxe-DkrM6paJKAB2AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 10:33:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:33:43.031032 2026] [security2:error] [pid 28342:tid 28342] [client 181.215.65.37:22763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.147"] [uri "/wp-content/.env"] [unique_id "asYgBwpesan9mS3CTj3i6QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-30 17:08:15
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dont-eat-the-pudding.online | URI: //wp-includes/ID3/license.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-09-26 00:00:05
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-25 17:27:56
(2 weeks ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-09-25 00:51:30
(2 weeks ago)
(wplogin) Failed WordPress login from 181.215.65.37 (US/United States/-): 5 in the last 3600 secs (0 ...
show more
(wplogin) Failed WordPress login from 181.215.65.37 (US/United States/-): 5 in the last 3600 secs (0-122)
show less
Hacking
๐ธ๐ฌ
pusathosting.com
2026-09-24 22:10:04
(2 weeks ago)
24ds22 bruteforce
Brute-Force
Web App Attack