๐บ๐ธ
TPI-Abuse
2026-09-18 10:34:25
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:34:13.898507 2026] [security2:error] [pid 14088:tid 14088] [client 213.254.175.19:60765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.236"] [uri "/admin/.env"] [unique_id "aq0TpbHUJzcIMQRqfOR8BgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 07:27:24
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:27:13.599236 2026] [security2:error] [pid 27528:tid 27528] [client 213.254.175.19:51883] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.242"] [uri "/conf/.env"] [unique_id "aqzn0WlSZiFACJWdoM4NngAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 06:35:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:35:11.832330 2026] [security2:error] [pid 2114:tid 2114] [client 213.254.175.19:39731] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.100"] [uri "/old/.env"] [unique_id "aquKH9rfgXlnWH7jftohrAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 00:51:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 20:51:39.488979 2026] [security2:error] [pid 28546:tid 28546] [client 213.254.175.19:46761] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.50"] [uri "/admin/.env"] [unique_id "aqs5m0guJfdxhuyt_9mCKwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 19:11:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 15:11:12.836245 2026] [security2:error] [pid 26036:tid 26036] [client 213.254.175.19:27925] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.22"] [uri "/local/.env"] [unique_id "aqrp0FbHBjbkXpgpK_eujgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 18:19:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 14:19:38.206782 2026] [security2:error] [pid 28484:tid 28484] [client 213.254.175.19:21393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.70"] [uri "/admin/.env"] [unique_id "aqrduoBm-LauHqRnjwe1_wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 17:42:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:42:34.804808 2026] [security2:error] [pid 8795:tid 8795] [client 213.254.175.19:26763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.230"] [uri "/crm/.env"] [unique_id "aqrVCszO2hezCDtSBgxy1wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-07-27 17:33:23
(1 month ago)
213.254.175.19 - - [27/Jul/2026:17:54:39 +0200] "POST /wp-login.php HTTP/1.1" 200 16606 "-" "Mozilla ...
show more
213.254.175.19 - - [27/Jul/2026:17:54:39 +0200] "POST /wp-login.php HTTP/1.1" 200 16606 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.0 Safari/605.1.15"
213.254.175.19 - - [27/Jul/2026:18:48:47 +0200] "POST /wp-login.php HTTP/1.1" 200 16607 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
213.254.175.19 - - [27/Jul/2026:19:33:22 +0200] "POST /wp-login.php HTTP/1.1" 200 16608 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-05-29 08:07:21
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-03-14 21:15:21
(6 months ago)
1.859 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-20 02:14:00
(6 months ago)
(mod_security) mod_security (id:240000) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240000) triggered by 213.254.175.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 21:13:52.922556 2026] [security2:error] [pid 23929:tid 23929] [client 213.254.175.19:50345] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "arsenalfordemocracy.com"] [uri "/images/stories/themes.php"] [unique_id "aZfDYIggNOKkH66D4apEXQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Mr-Money
2026-02-16 06:43:54
(7 months ago)
scenario: crowdsecurity/modsecurity - events: 1 - Matched Data: phpinfo found within REQUEST_FILENAM ...
show more
scenario: crowdsecurity/modsecurity - events: 1 - Matched Data: phpinfo found within REQUEST_FILENAME: /_profiler/phpinfo
show less
Web App Attack
๐ซ๐ฎ
YF
2026-02-16 05:00:44
(7 months ago)
xmlrpc.php (Potential DDoS or brute force)
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-02-16 04:23:34
(7 months ago)
996 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐จ๐ญ
backslash
2026-01-18 17:25:01
(7 months ago)
Web Spam