πΊπΈ
TPI-Abuse
2026-09-20 06:16:59
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 02:16:56.295372 2026] [security2:error] [pid 6179:tid 6179] [client 213.254.175.77:56145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.120"] [uri "/.env"] [unique_id "aq96WCFpMbdYbrGKVy_PZQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
PhilGoode
2026-09-20 04:22:25
(4 days ago)
HTTP web-application probing on TCP 80 requested /conf/.env. Observed by a web honeypot.
Web App Attack
πΊπΈ
technojoe99
2026-09-20 03:30:29
(4 days ago)
Exploit scan from 213.254.175.77. GET /new/.env HTTP/1.1.
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 08:47:09
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 04:46:48.191082 2026] [security2:error] [pid 4959:tid 4959] [client 213.254.175.77:53863] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.215"] [uri "/app/config/.env"] [unique_id "aqz6eES9XD4m89qY-U-OJQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Vaction
2026-09-18 03:15:04
(6 days ago)
213.254.175.77 - - [18/Sep/2026:05:15:04 +0200] "GET /wp-content/.env HTTP/1.1" 404 437 "-" "Mozilla ...
show more
213.254.175.77 - - [18/Sep/2026:05:15:04 +0200] "GET /wp-content/.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
show less
Hacking
Bad Web Bot
Web App Attack
π©πͺ
Vegascosmetics
2026-09-17 17:44:38
(6 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 13:16:57
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:16:43.818371 2026] [security2:error] [pid 21696:tid 21696] [client 213.254.175.77:46395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.168"] [uri "/new/.env"] [unique_id "aqvoO9T6LelXRHs1P-ruZAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 10:45:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:44:58.666621 2026] [security2:error] [pid 31869:tid 31869] [client 213.254.175.77:25225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.36"] [uri "/wp-content/.env"] [unique_id "aqvEqukNLkV6z9jv0yYyYgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
bescared
2026-09-17 05:04:09
(1 week ago)
F2B - Malicious activity detected. URL Probing. -c0423ad6-
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 01:10:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 21:10:08.510629 2026] [security2:error] [pid 26680:tid 26680] [client 213.254.175.77:62101] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.162"] [uri "/www/.env"] [unique_id "aqs98FA4DAnuoZcF_A3TFwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 19:41:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 15:41:05.045430 2026] [security2:error] [pid 18457:tid 18457] [client 213.254.175.77:22331] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.107"] [uri "/api/.env"] [unique_id "aqrw0fZSeaBtImXruOHEtQAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 17:42:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:42:35.193385 2026] [security2:error] [pid 8832:tid 8832] [client 213.254.175.77:39457] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.230"] [uri "/admin/.env"] [unique_id "aqrVC4k3_J47yxbRy1I89gAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
SentinalX by uzumaru
2026-09-04 05:48:24
(2 weeks ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: login.live.com:443
show less
Open Proxy
Port Scan
π©πͺ
gadix
2026-07-27 16:31:34
(1 month ago)
213.254.175.77 - - [27/Jul/2026:16:53:26 +0200] "POST /wp-login.php HTTP/1.1" 200 16607 "-" "Mozilla ...
show more
213.254.175.77 - - [27/Jul/2026:16:53:26 +0200] "POST /wp-login.php HTTP/1.1" 200 16607 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
213.254.175.77 - - [27/Jul/2026:18:05:15 +0200] "POST /wp-login.php HTTP/1.1" 200 3317 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/17.0 Safari/605.1.15"
213.254.175.77 - - [27/Jul/2026:18:31:32 +0200] "POST /wp-login.php HTTP/1.1" 200 16608 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7
...
show less
Web App Attack
πΈπ¬
securejdprop
2026-07-19 16:11:05
(2 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing.
Hacking
Web App Attack