πΊπΈ
TPI-Abuse
2026-09-16 15:15:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:15:19.607814 2026] [security2:error] [pid 32114:tid 32114] [client 213.254.175.37:50141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.115"] [uri "/wp-content/.env"] [unique_id "aqqyh9WuZgzFU6nCATHTgQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 12:37:13
(1 week ago)
automatically banned
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 12:35:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:34:48.473252 2026] [security2:error] [pid 9983:tid 9983] [client 213.254.175.37:22387] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.146"] [uri "/web146.dnchosting.com/.env"] [unique_id "aqqM6NY5_EkSRB1yGRZ_qwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 10:10:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:10:15.097302 2026] [security2:error] [pid 24238:tid 24238] [client 213.254.175.37:56283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.42"] [uri "/base/.env"] [unique_id "aqprB8voXEGGQCWouAxAUQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 00:43:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:43:44.908640 2026] [security2:error] [pid 1816970:tid 1816970] [client 213.254.175.37:57057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.183"] [uri "/app/config/.env"] [unique_id "aqnmQD5d74Muo8RH9uKGUgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-15 22:41:53
(1 week ago)
High-confidence malicious configuration/VCS probe
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 19:17:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:17:01.112911 2026] [security2:error] [pid 17055:tid 17055] [client 213.254.175.37:63781] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.11"] [uri "/base/.env"] [unique_id "aqmZrSFcJYDjy1xHjvqnzQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
afleventoffice.com.au
2026-09-15 01:12:29
(1 week ago)
GET /wp-admin/.env HTTP/1.1
Web App Attack
π«π·
Baking333
2026-07-14 13:14:07
(2 months ago)
[redacted] 213.254.175.37 - - [14/Jul/2026:14:14:03 +0100] "GET //wordpress/ HTTP/1.1" 301 5836 0/38 ...
show more
[redacted] 213.254.175.37 - - [14/Jul/2026:14:14:03 +0100] "GET //wordpress/ HTTP/1.1" 301 5836 0/383 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36" [redacted] 213.254.175.37 - - [14/Jul/2026:14:14:05 +0100] "GET /wordpress HTTP/1.1" 302 1559 0/134035 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
πͺπΈ
masterguru
2026-07-13 08:43:40
(2 months ago)
(wplogin) Failed WordPress login from 213.254.175.37 (US/United States/-): 5 in the last 3600 secs ( ...
show more
(wplogin) Failed WordPress login from 213.254.175.37 (US/United States/-): 5 in the last 3600 secs (0-122)
show less
Hacking
π«π·
dynamix
2026-07-13 05:24:32
(2 months ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-07-13 03:49:34
(2 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
GB/United Kingdom/-
Web App Attack
πΊπΈ
mnsf
2026-05-25 17:05:10
(4 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
π§π·
dominioz
2026-05-24 10:47:23
(4 months ago)
2026-05-24 10:46:46 GET /.well-known/void - - 213.254.175.37 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+A ...
show more
2026-05-24 10:46:46 GET /.well-known/void - - 213.254.175.37 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:48 GET /1993 - - 213.254.175.37 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:49 GET /.well-known/oauth-authorization-server - - 213.254.175.37 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:50 GET /25 - - 213.254.175.37 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
...
show less
Web App Attack
π§π·
SOC PR
2026-05-20 06:11:06
(4 months ago)
IPS: Web Server Exposed Git Repository Information Disclosure.
Hacking