๐บ๐ธ
TPI-Abuse
2026-09-20 08:24:14
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 04:24:01.953204 2026] [security2:error] [pid 28239:tid 28239] [client 213.254.175.3:33077] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.64.150.240"] [uri "/new/.env"] [unique_id "aq-YIfkMkLUgKPG8ig18KgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
technojoe99
2026-09-20 03:30:32
(3 days ago)
Exploit scan from 213.254.175.3. GET /admin/.env HTTP/1.1.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 07:50:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 03:50:09.362685 2026] [security2:error] [pid 31293:tid 31293] [client 213.254.175.3:44331] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.99"] [uri "/.env"] [unique_id "aq4-sQhk9Orz9FAHasRRpwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 00:17:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 20:17:28.132139 2026] [security2:error] [pid 24971:tid 24971] [client 213.254.175.3:23653] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.169"] [uri "/.env"] [unique_id "aq3UmMtVj_aG2Ne6qrdfvgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 12:57:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 08:57:00.581218 2026] [security2:error] [pid 21622:tid 21622] [client 213.254.175.3:50365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.47"] [uri "/app/.env"] [unique_id "aq01HHnRetvpYNTTZzEIIQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 10:34:34
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:34:11.585299 2026] [security2:error] [pid 24597:tid 24597] [client 213.254.175.3:38727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.236"] [uri "/vendor/.env"] [unique_id "aq0To4evVFET0GNja6_HDAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 17:40:55
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2017-9841
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 10:45:39
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:45:04.657484 2026] [security2:error] [pid 31869:tid 31869] [client 213.254.175.3:64513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.36"] [uri "/app/config/.env"] [unique_id "aqvEsOkNLkV6z9jv0yYyZgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 01:10:09
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:09:58.177714 2026] [security2:error] [pid 26681:tid 26681] [client 213.254.175.3:21975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.162"] [uri "/conf/.env"] [unique_id "aqs95nKgi961TbLy9NRdmAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 21:45:30
(6 days ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /.env | ua: Mozilla/5.0 (Window ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /.env | ua: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36 | 2026-09-16 21:45 UTC
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 19:35:26
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 15:35:05.284147 2026] [security2:error] [pid 4648:tid 4648] [client 213.254.175.3:38697] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.66"] [uri "/local/.env"] [unique_id "aqrvaRhzHFCPaqcVo8k7bAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
SentinalX by uzumaru
2026-09-11 01:30:46
(1 week ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: login.live.com:443
show less
Open Proxy
Port Scan
๐ฏ๐ต
demonsword
2026-09-04 10:36:58
(2 weeks ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: login.live.com:443
show less
Open Proxy
Port Scan
๐ฉ๐ช
gadix
2026-07-27 19:01:15
(1 month ago)
213.254.175.3 - - [27/Jul/2026:20:18:33 +0200] "POST /wp-login.php HTTP/1.1" 200 3317 "-" "Mozilla/5 ...
show more
213.254.175.3 - - [27/Jul/2026:20:18:33 +0200] "POST /wp-login.php HTTP/1.1" 200 3317 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36"
213.254.175.3 - - [27/Jul/2026:21:00:55 +0200] "POST /wp-login.php HTTP/1.1" 200 16608 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36"
213.254.175.3 - - [27/Jul/2026:21:01:15 +0200] "POST /wp-login.php HTTP/1.1" 200 16603 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-06-04 22:05:08
(3 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack