๐ฉ๐ช
Vegascosmetics
2026-09-17 17:44:50
(1 hour ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 13:16:45
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:16:41.905164 2026] [security2:error] [pid 17725:tid 17725] [client 213.254.175.152:49683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.168"] [uri "/.env"] [unique_id "aqvoOQLCoIXk5E1QXh5c3gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:11:03
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:10:50.089568 2026] [security2:error] [pid 337994:tid 337994] [client 213.254.175.152:43721] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.181"] [uri "/admin/.env"] [unique_id "aqvYynbM_BEEs7mLtawbMQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 10:59:20
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:59:02.383770 2026] [security2:error] [pid 2548:tid 2548] [client 213.254.175.152:62029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.73"] [uri "/crm/.env"] [unique_id "aqvH9qoRf-OeQYM9JolkpwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 07:28:33
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 03:28:16.073956 2026] [security2:error] [pid 26865:tid 26865] [client 213.254.175.152:27271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.118"] [uri "/vendor/laravel/.env"] [unique_id "aquWkHD7XUC4fyeTzYkdVQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 06:35:31
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:35:17.910295 2026] [security2:error] [pid 2194:tid 2194] [client 213.254.175.152:33195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.100"] [uri "/core/.env"] [unique_id "aquKJXPNsnC6kfDaZHeWmgAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 04:59:06
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:58:42.032023 2026] [security2:error] [pid 14188:tid 14287] [client 213.254.175.152:37539] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.201"] [uri "/app/config/.env"] [unique_id "aqtzglzWrjP-0_ynNOHzEAAAAc4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 01:25:24
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:24:47.844480 2026] [security2:error] [pid 31347:tid 31347] [client 213.254.175.152:44187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.148"] [uri "/library/.env"] [unique_id "aqtBXwr6UC0DWaOONI9luQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
SentinalX by uzumaru
2026-09-04 06:48:06
(1 week ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: login.live.com:443
show less
Open Proxy
Port Scan
๐ฉ๐ช
gadix
2026-07-27 17:42:08
(1 month ago)
213.254.175.152 - - [27/Jul/2026:16:37:26 +0200] "POST /wp-login.php HTTP/1.1" 200 3317 "-" "Mozilla ...
show more
213.254.175.152 - - [27/Jul/2026:16:37:26 +0200] "POST /wp-login.php HTTP/1.1" 200 3317 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
213.254.175.152 - - [27/Jul/2026:18:13:06 +0200] "POST /wp-login.php HTTP/1.1" 200 16603 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.0 Safari/605.1.15"
213.254.175.152 - - [27/Jul/2026:19:42:06 +0200] "POST /wp-login.php HTTP/1.1" 200 16603 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) A
...
show less
Web App Attack
๐ฏ๐ต
beon
2026-06-19 18:36:58
(2 months ago)
[DateTime=>2026-06-19T18:36:58Z (UTC)] , [HoneyPot_Hit=>once] , [HoneyPot=>/wp-login.php] , [total_H ...
show more
[DateTime=>2026-06-19T18:36:58Z (UTC)] , [HoneyPot_Hit=>once] , [HoneyPot=>/wp-login.php] , [total_Hit=>once] , [Keyword=>WordPress]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-03 08:06:47
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-01 09:05:09
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-05-26 13:05:13
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐ฉ๐ช
Savvii
2026-04-29 21:29:36
(4 months ago)
10 attempts against mh-misc-ban on bush
Web App Attack