Anonymous
2026-09-19 04:26:27
(5 hours ago)
Sensitive file access attempt
Hacking
🇫🇷
✨
2026-09-19 00:10:16
(9 hours ago)
Domain : redirect.netenergy.uk
Rule : env
2026-09-19 00:08:16 217.194.210.152 GET /sites/all/librari ...
show more
Domain : redirect.netenergy.uk
Rule : env
2026-09-19 00:08:16 217.194.210.152 GET /sites/all/libraries/mailchimp/.env - 80 - 213.254.175.241 HTTP/1.1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36 - 217.194.210.152 404 0 2 1503 260 124 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-18 15:19:55
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 11:19:40.132625 2026] [security2:error] [pid 15189:tid 15189] [client 213.254.175.241:24041] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.6"] [uri "/laravel/.env"] [unique_id "aq1WjHWWECZvKzUoD50iHwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Vaction
2026-09-18 03:15:05
(1 day ago)
213.254.175.241 - - [18/Sep/2026:05:15:05 +0200] "GET /library/.env HTTP/1.1" 404 437 "-" "Mozilla/5 ...
show more
213.254.175.241 - - [18/Sep/2026:05:15:05 +0200] "GET /library/.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
show less
Hacking
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-17 17:45:26
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 10:45:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:45:06.194714 2026] [security2:error] [pid 31007:tid 31007] [client 213.254.175.241:40991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.36"] [uri "/backend/.env"] [unique_id "aqvEssE6OfQoH0AJf-TReQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 07:28:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 03:28:17.844090 2026] [security2:error] [pid 23909:tid 23909] [client 213.254.175.241:29891] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.118"] [uri "/protected/.env"] [unique_id "aquWkd_sMQEazCSeeDOiZwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 06:20:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:20:24.324308 2026] [security2:error] [pid 10906:tid 10906] [client 213.254.175.241:20613] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.241"] [uri "/conf/.env"] [unique_id "aquGqOjAvZzXg3yAlvzXHgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
jfz-abuse
2026-09-17 05:51:00
(2 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 04:58:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:58:41.256829 2026] [security2:error] [pid 3981:tid 3999] [client 213.254.175.241:63663] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.201"] [uri "/laravel/.env"] [unique_id "aqtzgTku9LJ-mMHW4ho2mgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 01:10:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:10:08.128369 2026] [security2:error] [pid 24847:tid 24847] [client 213.254.175.241:42415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.162"] [uri "/newsite/.env"] [unique_id "aqs98ISs4b5MRG-08ksmdgAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 19:35:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 15:35:02.214975 2026] [security2:error] [pid 29309:tid 29309] [client 213.254.175.241:21079] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.66"] [uri "/.env"] [unique_id "aqrvZlMAcR93SkSPCrhgmQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 19:11:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 15:10:56.170317 2026] [security2:error] [pid 22979:tid 22979] [client 213.254.175.241:31049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.22"] [uri "/conf/.env"] [unique_id "aqrpwCbpRjWhQy-h8q7s6AAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇯🇵
demonsword
2026-09-04 07:36:09
(2 weeks ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: login.live.com:443
show less
Open Proxy
Port Scan
🇩🇪
gadix
2026-07-27 18:26:09
(1 month ago)
213.254.175.241 - - [27/Jul/2026:19:34:37 +0200] "POST /wp-login.php HTTP/1.1" 200 3317 "-" "Mozilla ...
show more
213.254.175.241 - - [27/Jul/2026:19:34:37 +0200] "POST /wp-login.php HTTP/1.1" 200 3317 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.0 Safari/605.1.15"
213.254.175.241 - - [27/Jul/2026:20:26:04 +0200] "POST /wp-login.php HTTP/1.1" 200 16608 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
213.254.175.241 - - [27/Jul/2026:20:26:04 +0200] "POST /wp-login.php HTTP/1.1" 200 16609 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_1
...
show less
Web App Attack