๐ฎ๐ช
AutosOnShow
2026-09-26 12:15:07
(23 hours ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-26 12:14:41.486 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-25 13:47:04
(1 day ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-25 13:46:31.898 |
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-25 03:27:05
(2 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-25 03:26:15.104 |
Web App Attack
๐ซ๐ท
spot
2026-09-04 06:20:23
(3 weeks ago)
195.63.17.82 - - [04/Sep/2026:07:20:23 +0100] "GET http://178.18.251.117/.env HTTP/1.1" 404 522 "-" ...
show more
195.63.17.82 - - [04/Sep/2026:07:20:23 +0100] "GET http://178.18.251.117/.env HTTP/1.1" 404 522 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36"
...
show less
Web App Attack
VPN IP
๐ซ๐ฎ
[email protected]
2026-03-30 20:24:56
(5 months ago)
Attack attempt against Interwebbi servers; *Port Scan* detected from 195.63.17.82 (CA/Canada/-). 5 h ...
show more
Attack attempt against Interwebbi servers; *Port Scan* detected from 195.63.17.82 (CA/Canada/-). 5 hits in the last 140 seconds; IP: 195.63.17.82; Ports: *; Direction: 0; Trigger: PS_LIMIT;
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-14 20:40:51
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.17.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.17.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 16:40:39.494017 2026] [security2:error] [pid 3299603:tid 3299603] [client 195.63.17.82:56494] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.nekstlevel.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.nekstlevel.com"] [uri "/wp-login.php"] [unique_id "abXHx-T2bbZIpYiD1LyYtwAAACA"], referer: https://www.nekstlevel.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 18:00:47
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.17.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.17.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 14:00:43.032472 2026] [security2:error] [pid 4681:tid 4681] [client 195.63.17.82:43654] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||kerrywood.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "kerrywood.com"] [uri "/wp-login.php"] [unique_id "aa8Ky8RpV8ksP6-Nf6j1ygAAAAQ"], referer: https://kerrywood.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-05 04:39:15
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 195.63.17.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 195.63.17.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 23:39:12.011840 2026] [security2:error] [pid 17765:tid 17765] [client 195.63.17.82:32814] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||univey.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "univey.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aakI8ORd2tVBmnClJGLTpAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-02 15:04:24
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.17.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.17.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 10:04:19.838948 2026] [security2:error] [pid 5514:tid 5514] [client 195.63.17.82:52808] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.geriterry.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.geriterry.com"] [uri "/wp-login.php"] [unique_id "aaWm884N5uMV61TGJnOxqwAAAB0"], referer: http://geriterry.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack