๐ซ๐ท
id2i
2026-09-19 10:55:23
(1 week ago)
2026-09-19T12:55:22.712670+02:00 coraza-spoa[262622]: [client "213.254.175.56"] Coraza: Access denie ...
show more
2026-09-19T12:55:22.712670+02:00 coraza-spoa[262622]: [client "213.254.175.56"] Coraza: Access denied (phase 2). Inbound Anomaly Score Exceeded (Total Score: 8)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 00:17:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 20:17:30.090314 2026] [security2:error] [pid 12898:tid 12898] [client 213.254.175.56:45739] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.169"] [uri "/new/.env"] [unique_id "aq3Umv51yQErpmybDI-XDgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 10:34:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:34:12.739323 2026] [security2:error] [pid 15174:tid 15174] [client 213.254.175.56:58997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.236"] [uri "/api/.env"] [unique_id "aq0TpJQBMQ3rhzR0-xfhLQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 07:27:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:27:26.176388 2026] [security2:error] [pid 22697:tid 22697] [client 213.254.175.56:25273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.242"] [uri "/sites/all/libraries/mailchimp/.env"] [unique_id "aqzn3mbOv6eN9-3Hz-IL9wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 01:53:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 21:53:32.693219 2026] [security2:error] [pid 24834:tid 24834] [client 213.254.175.56:34481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.58"] [uri "/backend/.env"] [unique_id "aqyZnBoXrokvUdUItlcpQQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
cnaize
2026-09-18 01:13:45
(1 week ago)
Malicious activity blocked by Meds firewall
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-18 00:43:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 20:43:38.727134 2026] [security2:error] [pid 31414:tid 31414] [client 213.254.175.56:57359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.244"] [uri "/apps/.env"] [unique_id "aqyJOhsyw3rVI1ixd-0u8gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:11:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:10:49.700496 2026] [security2:error] [pid 329327:tid 329327] [client 213.254.175.56:35079] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.181"] [uri "/crm/.env"] [unique_id "aqvYyR22g3sk2ICzPhMV6AAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 10:59:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:59:10.649719 2026] [security2:error] [pid 1832:tid 1832] [client 213.254.175.56:31289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.73"] [uri "/www/.env"] [unique_id "aqvH_hXa0oRK-shVc1kC4QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 09:37:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:36:53.875274 2026] [security2:error] [pid 16972:tid 16972] [client 213.254.175.56:38887] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.195"] [uri "/cgi-bin/.env"] [unique_id "aqu0tZKbNKSFzjX5D2rS9QAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 00:51:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 20:51:36.914293 2026] [security2:error] [pid 28546:tid 28546] [client 213.254.175.56:34409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.50"] [uri "/vendor/.env"] [unique_id "aqs5mEguJfdxhuyt_9mCKgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 19:39:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 15:39:44.141938 2026] [security2:error] [pid 5091:tid 5091] [client 213.254.175.56:63905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.6"] [uri "/wp-content/.env"] [unique_id "aqrwgJGOixiSAbrn-jsdcgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 18:19:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 14:19:39.789497 2026] [security2:error] [pid 27800:tid 27800] [client 213.254.175.56:33411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.70"] [uri "/apps/.env"] [unique_id "aqrdu_7Zh-XrCAX4eIWY9gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
SentinalX by uzumaru
2026-09-11 02:12:02
(2 weeks ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: login.live.com:443
show less
Open Proxy
Port Scan
๐ฏ๐ต
SentinalX by uzumaru
2026-09-04 06:17:42
(3 weeks ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: login.live.com:443
show less
Open Proxy
Port Scan