๐จ๐ฆ
polycoda
2026-09-20 11:07:20
(2 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 05:51:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 01:51:41.270374 2026] [security2:error] [pid 18558:tid 18558] [client 213.254.175.68:38885] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.180"] [uri "/newsite/.env"] [unique_id "aq90bTxqWEMMDy0u8NmUpAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
PhilGoode
2026-09-20 04:22:34
(3 days ago)
HTTP web-application probing on TCP 80 requested /vendor/.env and /cgi-bin/.env. Observed by a web h ...
show more
HTTP web-application probing on TCP 80 requested /vendor/.env and /cgi-bin/.env. Observed by a web honeypot.
show less
Web App Attack
๐บ๐ธ
technojoe99
2026-09-20 03:30:25
(3 days ago)
Exploit scan from 213.254.175.68. GET /.env HTTP/1.1.
Web App Attack
Anonymous
2026-09-19 04:26:23
(4 days ago)
Sensitive file access attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-18 12:57:33
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 08:56:54.491793 2026] [security2:error] [pid 20907:tid 20907] [client 213.254.175.68:60025] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.47"] [uri "/conf/.env"] [unique_id "aq01FlgVUxKjPQwf8n1r6wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 11:32:37
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 07:32:24.795579 2026] [security2:error] [pid 31209:tid 31230] [client 213.254.175.68:23933] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.80"] [uri "/cgi-bin/.env"] [unique_id "aq0hSMGahgHRcNfC6TAZnwAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-18 10:55:39
(4 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 213.254.175.68 (US/United States/-): 1 i ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 213.254.175.68 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 213.254.175.68 - - [18/Sep/2026:12:55:34 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" "-" host=145.239.233.176
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-18 10:34:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:34:13.122726 2026] [security2:error] [pid 15179:tid 15179] [client 213.254.175.68:39859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.236"] [uri "/blog/.env"] [unique_id "aq0TpeOuAGI_J3J3xVD2XwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 07:27:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:27:16.845377 2026] [security2:error] [pid 28380:tid 28380] [client 213.254.175.68:55045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.242"] [uri "/api/.env"] [unique_id "aqzn1GGhVU4_zGUrPilOpgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 01:53:37
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 21:53:26.038468 2026] [security2:error] [pid 23414:tid 23414] [client 213.254.175.68:30861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.58"] [uri "/library/.env"] [unique_id "aqyZllFZBcKNlK4ciPnKPQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 09:37:21
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:36:57.573684 2026] [security2:error] [pid 20634:tid 20634] [client 213.254.175.68:26967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.195"] [uri "/protected/.env"] [unique_id "aqu0uR3kknjwfrr0Zp-kvgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 06:35:17
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:35:09.288819 2026] [security2:error] [pid 2116:tid 2116] [client 213.254.175.68:57655] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.100"] [uri "/wp-admin/.env"] [unique_id "aquKHelLOqN3-eSU0O77GAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 01:10:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:10:09.282900 2026] [security2:error] [pid 25315:tid 25315] [client 213.254.175.68:64587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.162"] [uri "/database/.env"] [unique_id "aqs98dIrBlE_a4PDlSjqVAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 19:41:18
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 15:41:05.430195 2026] [security2:error] [pid 18458:tid 18458] [client 213.254.175.68:57123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.107"] [uri "/blog/.env"] [unique_id "aqrw0Z1Aax50I3YTdSIJtQAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack