πΊπΈ
wteiken
2026-02-22 17:11:11
(6 months ago)
2026-02-22T12:11:08.126551-05:00 rocinante.teiken.net kernel: [60093.445906] syn_limit:IN=ens5 OUT= ...
show more
2026-02-22T12:11:08.126551-05:00 rocinante.teiken.net kernel: [60093.445906] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=213.139.77.109 DST=192.168.16.119 LEN=52 TOS=0x00 PREC=0x00 TTL=119 ID=8170 DF PROTO=TCP SPT=56194 DPT=443 WINDOW=64240 RES=0x00 CWR ECE SYN URGP=0
2026-02-22T12:11:08.142311-05:00 rocinante.teiken.net kernel: [60093.464013] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=213.139.77.109 DST=192.168.16.119 LEN=52 TOS=0x00 PREC=0x00 TTL=118 ID=8171 DF PROTO=TCP SPT=56196 DPT=443 WINDOW=64240 RES=0x00 CWR ECE SYN URGP=0
2026-02-22T12:11:09.189829-05:00 rocinante.teiken.net kernel: [60094.511518] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=213.139.77.109 DST=192.168.16.119 LEN=52 TOS=0x00 PREC=0x00 TTL=118 ID=8183 DF PROTO=TCP SPT=56196 DPT=443 WINDOW=64240 RES=0x00 CWR ECE SYN URGP=0
2026-02-22T12:11:09.220643-05:00 rocinante.teiken.net kernel: [60094.542324] syn_limit:IN=ens5 OUT= MAC
...
show less
Port Scan
π©πͺ
Skyrider
2026-02-15 10:40:27
(6 months ago)
213.139.77.109 - - [15/Feb/2026:11:39:58 +0100] "GET / HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows N ...
show more
213.139.77.109 - - [15/Feb/2026:11:39:58 +0100] "GET / HTTP/2.0" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
213.139.77.109 - - [15/Feb/2026:11:40:03 +0100] "GET /checkout HTTP/2.0" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
213.139.77.109 - - [15/Feb/2026:11:40:07 +0100] "GET /buynow HTTP/2.0" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
213.139.77.109 - - [15/Feb/2026:11:40:22 +0100] "GET /cart HTTP/2.0" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
213.139.77.109 - - [15/Feb/2026:11:40:26 +0100] "GET /payment HTTP/2.0" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-02-15 05:04:07
(6 months ago)
Aggressive web scan
Web App Attack
πΊπΈ
wteiken
2026-02-14 05:41:32
(6 months ago)
rocinante.teiken.net:80 213.139.77.109:51608 - - [14/Feb/2026:00:41:32 -0500] "GET /.env HTTP/1.1" 3 ...
show more
rocinante.teiken.net:80 213.139.77.109:51608 - - [14/Feb/2026:00:41:32 -0500] "GET /.env HTTP/1.1" 301 619 "-" "python-requests/2.32.3"
rocinante.teiken.net:80 213.139.77.109:51614 - - [14/Feb/2026:00:41:32 -0500] "GET /.env HTTP/1.1" 301 637 "-" "python-requests/2.32.3"
rocinante.teiken.net:80 213.139.77.109:51615 - - [14/Feb/2026:00:41:32 -0500] "GET /.env HTTP/1.1" 301 619 "-" "python-requests/2.32.3"
rocinante.teiken.net:443 213.139.77.109:51612 - - [14/Feb/2026:00:41:32 -0500] "GET /.env HTTP/1.1" 404 3224 "-" "python-requests/2.32.3"
rocinante.teiken.net:443 213.139.77.109:51617 - - [14/Feb/2026:00:41:32 -0500] "GET /.env HTTP/1.1" 404 3224 "-" "python-requests/2.32.3"
rocinante.teiken.net:443 213.139.77.109:51620 - - [14/Feb/2026:00:41:32 -0500] "GET /.env HTTP/1.1" 404 3234 "-" "python-requests/2.32.3"
mta-sts.teiken.org:80 213.139.77.109:51609 - - [14/Feb/2026:00:41:32 -0500] "GET /.env HTTP/1.1" 301 631 "-" "python-requests/2.32.3"
www.teiken.org:80 213.139.77.109:51616 - - [
...
show less
Web App Attack
Anonymous
2026-02-14 02:49:19
(6 months ago)
Aggressive web scan
Web App Attack
Anonymous
2026-02-11 16:20:27
(6 months ago)
[Wed Feb 11 10:20:27.273263 2026] [authz_core:error] [pid 2293681:tid 2293718] [client 213.139.77.10 ...
show more
[Wed Feb 11 10:20:27.273263 2026] [authz_core:error] [pid 2293681:tid 2293718] [client 213.139.77.109:57543] AH01630: client denied by server configuration: /var/www/html/.env
[Wed Feb 11 10:20:27.284272 2026] [authz_core:error] [pid 2293681:tid 2293725] [client 213.139.77.109:57541] AH01630: client denied by server configuration: /var/www/html/.env
[Wed Feb 11 10:20:27.499449 2026] [authz_core:error] [pid 2293681:tid 2293715] [client 213.139.77.109:57561] AH01630: client denied by server configuration: /var/www/html/.env
[Wed Feb 11 10:20:27.511828 2026] [authz_core:error] [pid 2293681:tid 2293724] [client 213.139.77.109:57560] AH01630: client denied by server configuration: /var/www/html/.env
[Wed Feb 11 10:20:27.512981 2026] [authz_core:error] [pid 2367183:tid 2367227] [client 213.139.77.109:57569] AH01630: client denied by server configuration: /var/www/html/.env
...
show less
Brute-Force
πΊπΈ
wteiken
2026-02-11 12:25:22
(6 months ago)
mta-sts.teiken.org:80 213.139.77.109:49236 - - [11/Feb/2026:07:25:21 -0500] "GET /.env HTTP/1.1" 301 ...
show more
mta-sts.teiken.org:80 213.139.77.109:49236 - - [11/Feb/2026:07:25:21 -0500] "GET /.env HTTP/1.1" 301 631 "-" "python-requests/2.32.5"
www.teiken.org:80 213.139.77.109:49237 - - [11/Feb/2026:07:25:21 -0500] "GET /.env HTTP/1.1" 301 619 "-" "python-requests/2.32.5"
rocinante.teiken.net:80 213.139.77.109:49242 - - [11/Feb/2026:07:25:22 -0500] "GET /.env HTTP/1.1" 301 637 "-" "python-requests/2.32.5"
mta-sts.teiken.org:443 213.139.77.109:49241 - - [11/Feb/2026:07:25:22 -0500] "GET /.env HTTP/1.1" 404 3283 "-" "python-requests/2.32.5"
www.teiken.org:443 213.139.77.109:49243 - - [11/Feb/2026:07:25:22 -0500] "GET /.env HTTP/1.1" 404 3279 "-" "python-requests/2.32.5"
rocinante.teiken.net:80 213.139.77.109:49246 - - [11/Feb/2026:07:25:22 -0500] "GET /.env HTTP/1.1" 301 619 "-" "python-requests/2.32.5"
rocinante.teiken.net:443 213.139.77.109:49244 - - [11/Feb/2026:07:25:22 -0500] "GET /.env HTTP/1.1" 404 3234 "-" "python-requests/2.32.5"
rocinante.teiken.net:80 213.139.77.109:49249 - - [11/Feb/2
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-11 07:46:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 213.139.77.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.139.77.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 02:45:57.828454 2026] [security2:error] [pid 6256:tid 6298] [client 213.139.77.109:53007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.triplejjjranch.com"] [uri "/.env"] [unique_id "aYwztUhTOkafTblejSnI6gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-11 06:06:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 213.139.77.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.139.77.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 01:06:31.994100 2026] [security2:error] [pid 16250:tid 16250] [client 213.139.77.109:49372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heathbartley.com"] [uri "/.env"] [unique_id "aYwcZ-72eVm3llGSZJhO5gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-11 03:09:08
(6 months ago)
Aggressive web scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-11 02:09:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 213.139.77.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.139.77.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 21:09:36.021277 2026] [security2:error] [pid 31818:tid 31818] [client 213.139.77.109:50183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bordwell.com"] [uri "/.env"] [unique_id "aYvk4PeezKYOcCU_mAvlPQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
MPL
2026-02-07 07:08:43
(6 months ago)
tcp ports: 443,80 (8 or more attempts)
Port Scan
πΊπΈ
MPL
2026-02-07 05:43:57
(6 months ago)
tcp ports: 443,80 (10 or more attempts)
Port Scan
πΊπΈ
MPL
2026-02-07 05:19:47
(6 months ago)
tcp ports: 80,443 (5 or more attempts)
Port Scan
πΊπΈ
MPL
2026-02-07 03:58:06
(6 months ago)
tcp ports: 443,80 (3 or more attempts)
Port Scan