๐บ๐ธ
TPI-Abuse
2026-09-16 15:22:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:21:46.232747 2026] [security2:error] [pid 987:tid 987] [client 213.254.175.244:58595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.139"] [uri "/laravel/.env"] [unique_id "aqq0Ci8H61ckmKcvk_uBDAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:05:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:05:11.095041 2026] [security2:error] [pid 19407:tid 19440] [client 213.254.175.244:26991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.85"] [uri "/.env"] [unique_id "aqqiFw_LulmWyAkLxId-3wAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:35:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:34:39.046701 2026] [security2:error] [pid 8784:tid 8784] [client 213.254.175.244:20833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.146"] [uri "/blog/.env"] [unique_id "aqqM32pVybpRzJgdp1uM8QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:10:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:10:11.612191 2026] [security2:error] [pid 22422:tid 22422] [client 213.254.175.244:38783] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.42"] [uri "/admin/.env"] [unique_id "aqprA2tCvM6RJ31rFw4dfQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-16 07:02:17
(2 days ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-3)
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-16 00:43:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:43:46.602015 2026] [security2:error] [pid 1817306:tid 1817306] [client 213.254.175.244:50153] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.183"] [uri "/backend/.env"] [unique_id "aqnmQjyMhrmwwDOXwN3wIAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:17:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:16:55.649333 2026] [security2:error] [pid 15115:tid 15115] [client 213.254.175.244:37065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.11"] [uri "/blog/.env"] [unique_id "aqmZpyfFbC-lv-ruTTAA2QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:11:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:11:05.151679 2026] [security2:error] [pid 4428:tid 4428] [client 213.254.175.244:44797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.238"] [uri "/crm/.env"] [unique_id "aqkZuXRz6RF6kfXjnlO6pgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
securejdprop
2026-07-19 16:10:26
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing.
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-07-13 08:41:55
(2 months ago)
(wplogin) Failed WordPress login from 213.254.175.244 (US/United States/-): 5 in the last 3600 secs ...
show more
(wplogin) Failed WordPress login from 213.254.175.244 (US/United States/-): 5 in the last 3600 secs (0-122)
show less
Hacking
๐ซ๐ท
dynamix
2026-07-13 02:33:46
(2 months ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐ง๐ท
dominioz
2026-05-24 10:47:58
(3 months ago)
2026-05-24 10:47:33 GET /bkup - - 213.254.175.244 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/ ...
show more
2026-05-24 10:47:33 GET /bkup - - 213.254.175.244 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:34 GET /cfm - - 213.254.175.244 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:35 GET /charts - - 213.254.175.244 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:37 GET /broadband - - 213.254.175.244 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
...
show less
Web App Attack
๐ฎ๐ฉ
fazar
2026-05-17 07:46:00
(4 months ago)
crowdsecurity/http-crawl-non_statics on node: bdj03
Web App Attack
Bad Web Bot
Anonymous
2026-05-02 12:05:03
(4 months ago)
suspicious request in access.log
Web App Attack
๐ง๐ช
cmbplf
2026-03-29 04:23:08
(5 months ago)
1.073 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot