๐บ๐ธ
TPI-Abuse
2026-09-20 05:51:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 01:51:37.337221 2026] [security2:error] [pid 7520:tid 7520] [client 213.254.175.194:21159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.180"] [uri "/apps/.env"] [unique_id "aq90aZ3GqKDqZoq1tpNlkQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 04:29:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 00:29:20.234058 2026] [security2:error] [pid 32043:tid 32043] [client 213.254.175.194:50925] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.251"] [uri "/conf/.env"] [unique_id "aq9hICGKoryZDcOWIbRZ_wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
PhilGoode
2026-09-20 04:22:25
(1 day ago)
HTTP web-application probing on TCP 80 requested the sensitive configuration file /.env. Observed by ...
show more
HTTP web-application probing on TCP 80 requested the sensitive configuration file /.env. Observed by a web honeypot.
show less
Web App Attack
๐บ๐ธ
wbsouza
2026-09-20 03:40:50
(1 day ago)
CrowdSec: infra/bad-path-probe โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ซ๐ท
id2i
2026-09-19 10:55:25
(2 days ago)
2026-09-19T12:55:24.995444+02:00 coraza-spoa[262622]: [client "213.254.175.194"] Coraza: Access deni ...
show more
2026-09-19T12:55:24.995444+02:00 coraza-spoa[262622]: [client "213.254.175.194"] Coraza: Access denied (phase 2). Inbound Anomaly Score Exceeded (Total Score: 8)
show less
Hacking
Web App Attack
๐ฎ๐น
LTM
2026-09-19 06:20:01
(2 days ago)
WebServer - Attempts to exploit
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-19 04:26:34
(2 days ago)
Sensitive file access attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-18 11:32:39
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 07:32:28.573325 2026] [security2:error] [pid 10648:tid 10661] [client 213.254.175.194:50937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.80"] [uri "/www/.env"] [unique_id "aq0hTH2kDMogGM6xH5D45gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 10:34:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:34:16.607795 2026] [security2:error] [pid 14088:tid 14088] [client 213.254.175.194:62269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.236"] [uri "/backend/.env"] [unique_id "aq0TqLHUJzcIMQRqfOR8BwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 08:47:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 04:46:45.216997 2026] [security2:error] [pid 4959:tid 4959] [client 213.254.175.194:31601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.215"] [uri "/blog/.env"] [unique_id "aqz6dUS9XD4m89qY-U-OJAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 07:27:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:27:21.841007 2026] [security2:error] [pid 22943:tid 22943] [client 213.254.175.194:35415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.242"] [uri "/core/.env"] [unique_id "aqzn2TgUr_tCodVVKKxx0wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LoneRider
2026-09-18 04:09:45
(3 days ago)
[18/Sep/2026:06:09:39.286081 +0200] aqy5gxfPenyJ_FiEzmKYogAAAAM 213.254.175.194 54896 127.0.0.1 7080 ...
show more
[18/Sep/2026:06:09:39.286081 +0200] aqy5gxfPenyJ_FiEzmKYogAAAAM 213.254.175.194 54896 127.0.0.1 7080
[18/Sep/2026:06:09:43.654789 +0200] aqy5h0BNthwCC3TWniw8mQAAAAI 213.254.175.194 41082 127.0.0.1 7080
[18/Sep/2026:06:09:45.202060 +0200] aqy5iZijG5FzbEGOekzu9QAAAAA 213.254.175.194 41108 127.0.0.1 7080
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-18 02:50:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 22:50:43.830365 2026] [security2:error] [pid 10731:tid 10731] [client 213.254.175.194:48895] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.190"] [uri "/conf/.env"] [unique_id "aqynA_9wDtBL_TpqPK71YgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 01:53:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 21:53:27.925024 2026] [security2:error] [pid 26483:tid 26483] [client 213.254.175.194:39583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.58"] [uri "/local/.env"] [unique_id "aqyZl9_NvlBEXRMbQatNzgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-17 17:44:27
(4 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack