๐บ๐ธ
TPI-Abuse
2026-09-16 15:22:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.129 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:21:42.926494 2026] [security2:error] [pid 31582:tid 31582] [client 213.254.175.129:63505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.139"] [uri "/old/.env"] [unique_id "aqq0BtMrH3Oe03-s6-PpKwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:10:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.129 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:10:10.853203 2026] [security2:error] [pid 24261:tid 24261] [client 213.254.175.129:58931] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.42"] [uri "/blog/.env"] [unique_id "aqprAh_jC4k3RQADSJPhOQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:33:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.129 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:33:05.050296 2026] [security2:error] [pid 822:tid 822] [client 213.254.175.129:22269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.99"] [uri "/library/.env"] [unique_id "aqnjweOMfALr_Wt4gxmw4QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:38:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.129 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:38:37.468900 2026] [security2:error] [pid 31711:tid 31719] [client 213.254.175.129:44655] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.82"] [uri "/newsite/.env"] [unique_id "aqmszRlZ4tW07tAjHdioCAAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:50:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.129 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:50:36.624503 2026] [security2:error] [pid 29838:tid 29838] [client 213.254.175.129:22943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.94"] [uri "/admin/.env"] [unique_id "aqmhjOi5Kh2Tp4qeOcA1KgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-13 04:06:14
(2 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
GB/United Kingdom/-
Web App Attack
๐ง๐ท
ICS Labs
2026-07-10 18:58:53
(2 months ago)
ICS Labs identified 213.254.175.129 as a malicious indicator from threat intelligence.
DDoS Attack
Port Scan
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
threatintelligence_bvc
2026-06-29 07:38:30
(2 months ago)
Brute-Force
๐ง๐ท
dominioz
2026-05-24 10:47:16
(3 months ago)
2026-05-24 10:46:39 GET /.passwd - - 213.254.175.129 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebK ...
show more
2026-05-24 10:46:39 GET /.passwd - - 213.254.175.129 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:40 GET /.profile - - 213.254.175.129 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:43 GET /.well-known/change-password - - 213.254.175.129 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:45 GET /.well-known/ni - - 213.254.175.129 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
...
show less
Web App Attack
๐ฎ๐ฉ
fazar
2026-05-17 07:46:27
(4 months ago)
crowdsecurity/http-crawl-non_statics on node: bdj03
Web App Attack
Bad Web Bot
Anonymous
2026-05-03 17:49:30
(4 months ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ง๐ช
cmbplf
2026-03-29 02:31:40
(5 months ago)
1.743 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ณ๐ฑ
EGP Abuse Dept
2026-02-24 01:17:46
(6 months ago)
Scanning for web/db/file exploits on security-seals.global
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-09 17:53:27
(7 months ago)
Blocking for trying to access an exploit file: /manager.php
Hacking
Anonymous
2026-02-09 17:05:25
(7 months ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (15/60 min)'; Requests=15
Port Scan