๐บ๐ธ
TPI-Abuse
2026-09-16 15:21:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.64 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:21:40.230942 2026] [security2:error] [pid 12839:tid 12839] [client 213.254.175.64:42879] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.139"] [uri "/.env"] [unique_id "aqq0BCNbzcIoQCe-JZxUtwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:18:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.64 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:18:30.708690 2026] [security2:error] [pid 12263:tid 12263] [client 213.254.175.64:50595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.217"] [uri "/backend/.env"] [unique_id "aqps9qqFPuFyBQsyUmkAFQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:43:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.64 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:43:40.762963 2026] [security2:error] [pid 1816873:tid 1816873] [client 213.254.175.64:22513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.183"] [uri "/old/.env"] [unique_id "aqnmPDj3XFhkkn_sIkOYpQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:38:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.64 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:38:31.629962 2026] [security2:error] [pid 31711:tid 31734] [client 213.254.175.64:63363] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.82"] [uri "/crm/.env"] [unique_id "aqmsxxlZ4tW07tAjHdin-wAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:17:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.64 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:17:04.271067 2026] [security2:error] [pid 17111:tid 17111] [client 213.254.175.64:48423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.11"] [uri "/database/.env"] [unique_id "aqmZsEJqNzOE8cQZksB1agAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-09-15 18:20:07
(1 week ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐น๐ท
neron
2026-08-02 06:16:22
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-31 21:06:18
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-07-13 08:43:40
(2 months ago)
(wplogin) Failed WordPress login from 213.254.175.64 (US/United States/-): 5 in the last 3600 secs ( ...
show more
(wplogin) Failed WordPress login from 213.254.175.64 (US/United States/-): 5 in the last 3600 secs (0-122)
show less
Hacking
๐ฆ๐บ
screwlooseit.com.au
2026-07-13 03:42:46
(2 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
GB/United Kingdom/-
Web App Attack
๐ซ๐ท
dynamix
2026-07-13 02:40:05
(2 months ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐ง๐ช
Scampi_ml
2026-06-10 13:37:15
(3 months ago)
12x HTTP 403/404 responses in short timeframe. Likely vulnerability scanner or brute-force attack on ...
show more
12x HTTP 403/404 responses in short timeframe. Likely vulnerability scanner or brute-force attack on web application paths.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-26 01:05:17
(4 months ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ง๐ท
dominioz
2026-05-24 10:47:49
(4 months ago)
2026-05-24 10:46:51 GET /403 - - 213.254.175.64 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/53 ...
show more
2026-05-24 10:46:51 GET /403 - - 213.254.175.64 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:46:53 GET /Browser - - 213.254.175.64 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:19 GET /appeal - - 213.254.175.64 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:21 GET /banned - - 213.254.175.64 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
...
show less
Web App Attack
๐ง๐ท
SOC PR
2026-05-20 06:10:02
(4 months ago)
IPS: Web Server Exposed Git Repository Information Disclosure.
Hacking