๐บ๐ธ
TPI-Abuse
2026-09-16 15:40:36
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:40:18.664053 2026] [security2:error] [pid 24917:tid 24917] [client 213.254.175.165:46045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.104"] [uri "/laravel/.env"] [unique_id "aqq4YtWnmHUio6uBn2JGJwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:35:10
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:34:40.970682 2026] [security2:error] [pid 8732:tid 8732] [client 213.254.175.165:26105] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.146"] [uri "/app/config/.env"] [unique_id "aqqM4LAjvJh9_t_bDhayLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:49:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:49:41.346052 2026] [security2:error] [pid 15441:tid 15441] [client 213.254.175.165:64029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.95"] [uri "/conf/.env"] [unique_id "aqn1teHb0qf6QSh0FcOQQwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:33:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:33:06.228537 2026] [security2:error] [pid 2588:tid 2588] [client 213.254.175.165:62825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.99"] [uri "/old/.env"] [unique_id "aqnjwiTaRnAkjWrCAuX83wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:38:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:38:34.748113 2026] [security2:error] [pid 31711:tid 31727] [client 213.254.175.165:41147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.82"] [uri "/backend/.env"] [unique_id "aqmsyhlZ4tW07tAjHdioAQAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-13 03:54:47
(2 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
GB/United Kingdom/-
Web App Attack
๐ง๐ท
ICS Labs
2026-07-10 18:53:20
(2 months ago)
ICS Labs identified 213.254.175.165 as a malicious indicator from threat intelligence.
DDoS Attack
Port Scan
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
mnsf
2026-06-04 01:05:03
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-05-26 12:05:10
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐ง๐ท
dominioz
2026-05-24 10:47:17
(3 months ago)
2026-05-24 10:46:39 GET /.svnignore - - 213.254.175.165 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleW ...
show more
2026-05-24 10:46:39 GET /.svnignore - - 213.254.175.165 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:40 GET /.listings - - 213.254.175.165 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:43 GET /.well-known/carddav - - 213.254.175.165 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:45 GET /.well-known/mud - - 213.254.175.165 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
...
show less
Web App Attack
Anonymous
2026-05-03 17:49:08
(4 months ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-03-29 21:51:17
(5 months ago)
Kingcopy(AI-IDS):IP is Probing for Wordpress vulnerabilities WTF:Banned
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-28 23:05:23
(5 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-01-22 13:05:10
(7 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-01-21 12:05:22
(7 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack