๐บ๐ธ
TPI-Abuse
2026-09-16 15:40:38
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:40:23.670528 2026] [security2:error] [pid 24368:tid 24368] [client 213.254.175.217:28479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.104"] [uri "/newsite/.env"] [unique_id "aqq4Z-_Ik1yWP8SNXeKd8wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:22:09
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:21:44.472620 2026] [security2:error] [pid 12839:tid 12839] [client 213.254.175.217:24073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.139"] [uri "/crm/.env"] [unique_id "aqq0CCNbzcIoQCe-JZxUuQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:35:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:34:39.814009 2026] [security2:error] [pid 10397:tid 10397] [client 213.254.175.217:31593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.146"] [uri "/admin/.env"] [unique_id "aqqM31aHcupL38wIboSTmQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:10:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:10:12.386877 2026] [security2:error] [pid 24208:tid 24208] [client 213.254.175.217:32917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.42"] [uri "/app/.env"] [unique_id "aqprBABPBzo9hmNRd6ss5AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:38:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:38:32.795618 2026] [security2:error] [pid 10143:tid 10155] [client 213.254.175.217:53887] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.82"] [uri "/app/.env"] [unique_id "aqmsyMV4yunqWwklqDpvAAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:50:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:50:38.026891 2026] [security2:error] [pid 29849:tid 29849] [client 213.254.175.217:50233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.94"] [uri "/laravel/.env"] [unique_id "aqmhjlNHI5p5MwY2mDsfcQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:11:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:11:04.748723 2026] [security2:error] [pid 4424:tid 4424] [client 213.254.175.217:27831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.238"] [uri "/blog/.env"] [unique_id "aqkZuFaYfrHypH3MOrRX5wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 09:12:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:12:21.124459 2026] [security2:error] [pid 13292:tid 13292] [client 213.254.175.217:35907] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.13"] [uri "/app/.env"] [unique_id "aqkL9VC-LTDryV_HQNmXRgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-09-15 01:12:32
(2 days ago)
GET /vendor/.env HTTP/1.1
Web App Attack
๐น๐ท
neron
2026-08-14 03:06:49
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ธ๐ฌ
securejdprop
2026-07-19 16:08:45
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing.
Hacking
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-13 03:24:52
(2 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
GB/United Kingdom/-
Web App Attack
๐บ๐ธ
mnsf
2026-05-28 13:05:04
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-05-25 18:05:18
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐ง๐ท
dominioz
2026-05-24 10:47:51
(3 months ago)
2026-05-24 10:47:27 GET /boot - - 213.254.175.217 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/ ...
show more
2026-05-24 10:47:27 GET /boot - - 213.254.175.217 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:28 GET /broken_link - - 213.254.175.217 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:29 GET /banking - - 213.254.175.217 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:29 GET /buynow - - 213.254.175.217 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
...
show less
Web App Attack