π±π»
garmtech.com
2026-09-18 13:45:00
(1 hour ago)
Attempted access to sensitive endpoint (/blog/.env) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/blog/.env) detected. Automated scan or unauthorized probing.
show less
Web App Attack
π©πͺ
paissangroup
2026-09-18 13:05:43
(1 hour ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 12:57:41
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 08:57:06.859692 2026] [security2:error] [pid 20906:tid 20906] [client 213.254.175.182:26541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.47"] [uri "/www/.env"] [unique_id "aq01IvCCF9qkb7rPtyTrsgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 11:32:27
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 07:32:18.804000 2026] [security2:error] [pid 1191:tid 1213] [client 213.254.175.182:50583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.80"] [uri "/new/.env"] [unique_id "aq0hQhsaMo2qigPrg6DaLwAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 08:47:06
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 04:46:52.433082 2026] [security2:error] [pid 4951:tid 4951] [client 213.254.175.182:58653] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.215"] [uri "/newsite/.env"] [unique_id "aqz6fMRy9EtOjaDx1xmqYgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 07:27:46
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:27:21.459333 2026] [security2:error] [pid 22697:tid 22697] [client 213.254.175.182:65319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.242"] [uri "/base/.env"] [unique_id "aqzn2WbOv6eN9-3Hz-IL9gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Vaction
2026-09-18 03:15:04
(11 hours ago)
213.254.175.182 - - [18/Sep/2026:05:15:04 +0200] "GET /wp-admin/.env HTTP/1.1" 404 437 "-" "Mozilla/ ...
show more
213.254.175.182 - - [18/Sep/2026:05:15:04 +0200] "GET /wp-admin/.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
show less
Hacking
Bad Web Bot
Web App Attack
π·πΊ
cnaize
2026-09-18 01:13:46
(13 hours ago)
Malicious activity blocked by Meds firewall
Port Scan
π©πͺ
Vegascosmetics
2026-09-17 17:44:25
(21 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 09:37:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:36:48.874767 2026] [security2:error] [pid 21213:tid 21213] [client 213.254.175.182:22523] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.195"] [uri "/new/.env"] [unique_id "aqu0sLhyvoeNEmDHJPmEYQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 01:10:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:09:58.959818 2026] [security2:error] [pid 24467:tid 24467] [client 213.254.175.182:49145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.162"] [uri "/wp-admin/.env"] [unique_id "aqs95idfYh-DqLlKYVpjSgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
gadix
2026-07-27 17:33:24
(1 month ago)
213.254.175.182 - - [27/Jul/2026:17:28:26 +0200] "POST /wp-login.php HTTP/1.1" 200 16606 "-" "Mozill ...
show more
213.254.175.182 - - [27/Jul/2026:17:28:26 +0200] "POST /wp-login.php HTTP/1.1" 200 16606 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36"
213.254.175.182 - - [27/Jul/2026:19:06:38 +0200] "POST /wp-login.php HTTP/1.1" 200 16602 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.0 Safari/605.1.15"
213.254.175.182 - - [27/Jul/2026:19:33:22 +0200] "POST /wp-login.php HTTP/1.1" 200 16604 "-" "Mozilla/5.0 (Windows NT 10
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 09:24:49
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 213.254.175.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 05:24:41.128314 2026] [security2:error] [pid 981472:tid 981472] [client 213.254.175.182:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 213.254.175.182 (+1 hits since last alert)|upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "upskirtcrazy.com"] [uri "/xmlrpc.php"] [unique_id "amSA2ce_XGMP3Fup3aA7SwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-06-03 03:05:18
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-05-29 03:05:24
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack