๐ฉ๐ช
HoneyPot-FrPri
2026-09-16 15:35:49
(2 weeks ago)
213.254.175.36 - - 181.214.99.65 [16/Sep/2026:17:35:38 +0200] "GET /wp-content/.env HTTP/1.1" 404 18 ...
show more
213.254.175.36 - - 181.214.99.65 [16/Sep/2026:17:35:38 +0200] "GET /wp-content/.env HTTP/1.1" 404 188 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safa
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Erpelstolz
2026-09-16 15:18:27
(2 weeks ago)
external host: 213.254.175.36 - - [16/Sep/2026:17:18:26 +0200] "GET /blog/.env HTTP/1.1" 404 258 "-" ...
show more
external host: 213.254.175.36 - - [16/Sep/2026:17:18:26 +0200] "GET /blog/.env HTTP/1.1" 404 258 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" CF-Ray:- CF-IP:-
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:35:03
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.36 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:34:37.015182 2026] [security2:error] [pid 8781:tid 8781] [client 213.254.175.36:45495] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.146"] [uri "/new/.env"] [unique_id "aqqM3Ybti_MXviyQ1P-IYQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 08:11:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.36 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:10:52.894556 2026] [security2:error] [pid 21835:tid 21835] [client 213.254.175.36:57077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.142"] [uri "/.env"] [unique_id "aqpPDHlPUJVpHWbJIhB3hwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:38:51
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.36 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:38:30.067186 2026] [security2:error] [pid 10064:tid 10081] [client 213.254.175.36:29945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.82"] [uri "/old/.env"] [unique_id "aqmsxt5AS0vLWKShG0WvswAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 09:06:04
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.36 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:05:41.833173 2026] [security2:error] [pid 7059:tid 7080] [client 213.254.175.36:23219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.133"] [uri "/www/.env"] [unique_id "aqkKZTIINOFhGZbjJo8QzwAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
securejdprop
2026-07-19 16:08:24
(2 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing.
Hacking
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-13 03:27:29
(2 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
GB/United Kingdom/-
Web App Attack
๐ซ๐ท
dynamix
2026-07-13 02:36:39
(2 months ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐ง๐ท
ICS Labs
2026-07-10 18:48:39
(2 months ago)
ICS Labs identified 213.254.175.36 as a malicious indicator from threat intelligence.
DDoS Attack
Port Scan
Hacking
Brute-Force
Exploited Host
๐ง๐ท
dominioz
2026-05-24 10:47:21
(4 months ago)
2026-05-24 10:46:41 GET /.git/config - - 213.254.175.36 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleW ...
show more
2026-05-24 10:46:41 GET /.git/config - - 213.254.175.36 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:44 GET /.well-known/apple-developer-merchantid-domain-association - - 213.254.175.36 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:46 GET /.well-known/openid-configuration - - 213.254.175.36 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:49 GET /2008 - - 213.254.175.36 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
...
show less
Web App Attack
๐ฎ๐ฉ
fazar
2026-05-17 07:46:22
(4 months ago)
crowdsecurity/http-crawl-non_statics on node: bdj03
Web App Attack
Bad Web Bot
๐ฏ๐ต
demonsword
2026-04-28 15:53:45
(5 months ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: api.ipvanish.com:443
show less
Open Proxy
Port Scan
๐ซ๐ท
Baking333
2026-03-29 18:19:45
(6 months ago)
[redacted] 213.254.175.36 - - [29/Mar/2026:19:19:43 +0100] "GET /[redacted] HTTP/1.1" 302 5287 0/688 ...
show more
[redacted] 213.254.175.36 - - [29/Mar/2026:19:19:43 +0100] "GET /[redacted] HTTP/1.1" 302 5287 0/68836 "-" "Mozilla/5.0" [redacted] 213.254.175.36 - - [29/Mar/2026:19:19:43 +0100] "GET /wp-admin/ HTTP/1.1" 301 4343 0/376 "-" "Mozilla/5.0"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-25 02:05:04
(6 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack