πΊπΈ
TPI-Abuse
2026-09-20 08:24:28
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 04:24:06.733646 2026] [security2:error] [pid 30931:tid 30931] [client 213.254.175.216:33177] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.64.150.240"] [uri "/app/.env"] [unique_id "aq-YJnQIvSO4jZkrhYufXQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 06:51:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 02:51:47.565259 2026] [security2:error] [pid 2456716:tid 2456716] [client 213.254.175.216:41807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.188"] [uri "/.env"] [unique_id "aq-Cg8Yp4EsDJv_NMXnYVwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
technojoe99
2026-09-20 03:30:28
(1 week ago)
Exploit scan from 213.254.175.216. GET /wp-admin/.env HTTP/1.1.
Web App Attack
Anonymous
2026-09-20 02:11:57
(1 week ago)
[Sun Sep 20 04:11:54.066939 2026] [access_compat:error] [pid 2331200:tid 2331200] [client 213.254.17 ...
show more
[Sun Sep 20 04:11:54.066939 2026] [access_compat:error] [pid 2331200:tid 2331200] [client 213.254.175.216:43043] AH01797: client denied by server configuration: /var/www/html/old
[Sun Sep 20 04:11:56.767931 2026] [access_compat:error] [pid 2302421:tid 2302421] [client 213.254.175.216:46097] AH01797: client denied by server configuration: /var/www/html/blog
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-19 19:45:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 15:44:46.298796 2026] [security2:error] [pid 32564:tid 32564] [client 213.254.175.216:36053] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.57"] [uri "/old/.env"] [unique_id "aq7mLqC6nJeKnJS7XDDqLQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
msavo
2026-09-19 14:03:40
(1 week ago)
CIR Sentinel: env_probe_permanent; 1 requests in 60s; targets=/conf/.env; permanently blocked by the ...
show more
CIR Sentinel: env_probe_permanent; 1 requests in 60s; targets=/conf/.env; permanently blocked by the firewall.
show less
Web App Attack
π«π·
id2i
2026-09-19 10:55:20
(1 week ago)
2026-09-19T12:55:19.862365+02:00 coraza-spoa[262622]: [client "213.254.175.216"] Coraza: Access deni ...
show more
2026-09-19T12:55:19.862365+02:00 coraza-spoa[262622]: [client "213.254.175.216"] Coraza: Access denied (phase 2). Inbound Anomaly Score Exceeded (Total Score: 8)
show less
Hacking
Web App Attack
Anonymous
2026-09-19 04:26:14
(1 week ago)
Sensitive file access attempt
Hacking
Anonymous
2026-09-18 21:40:21
(2 weeks ago)
213.254.175.216 - - [18/Sep/2026:23:40:21 +0200] "GET /library/.env HTTP/1.1" 301 169 "-" "Mozilla/5 ...
show more
213.254.175.216 - - [18/Sep/2026:23:40:21 +0200] "GET /library/.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 12:57:46
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 08:56:59.801349 2026] [security2:error] [pid 20897:tid 20897] [client 213.254.175.216:61301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.47"] [uri "/admin/.env"] [unique_id "aq01Gzzp_lBeqnAcZWqNmQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 10:34:17
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:34:12.349158 2026] [security2:error] [pid 7149:tid 7149] [client 213.254.175.216:58471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.236"] [uri "/local/.env"] [unique_id "aq0TpPOV4dHW3KNsihsxIgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 07:27:29
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:27:13.991701 2026] [security2:error] [pid 28380:tid 28380] [client 213.254.175.216:47941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.242"] [uri "/wp-content/.env"] [unique_id "aqzn0WGhVU4_zGUrPilOpQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 01:53:31
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 21:53:25.655903 2026] [security2:error] [pid 26483:tid 26483] [client 213.254.175.216:29223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.58"] [uri "/wp-admin/.env"] [unique_id "aqyZld_NvlBEXRMbQatNzQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
ingroscart.it
2026-09-17 22:09:13
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-17 12:29:45
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:29:40.658563 2026] [security2:error] [pid 5195:tid 5195] [client 213.254.175.216:36963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.190"] [uri "/conf/.env"] [unique_id "aqvdNClXIarkjd-t2o5-SgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack