🇺🇸
TPI-Abuse
2026-09-15 19:50:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.78 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:50:40.794714 2026] [security2:error] [pid 29848:tid 29848] [client 213.254.175.78:50715] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.94"] [uri "/src/.env"] [unique_id "aqmhkB-RKMw8QajXi4hyWAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 19:17:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.78 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:17:00.288474 2026] [security2:error] [pid 17053:tid 17053] [client 213.254.175.78:57639] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.11"] [uri "/backend/.env"] [unique_id "aqmZrJEBlizl7IzWupwm8wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-15 16:19:03
(7 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 10:11:07
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.78 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:10:59.799233 2026] [security2:error] [pid 4427:tid 4427] [client 213.254.175.78:48495] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.238"] [uri "/.env"] [unique_id "aqkZs9HW8jCHHtpjm93pWQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 09:12:27
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.78 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:12:19.553611 2026] [security2:error] [pid 25819:tid 25819] [client 213.254.175.78:41601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.13"] [uri "/blog/.env"] [unique_id "aqkL8_Nc3Aicr1AoxOl_2AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Dentax
2026-08-25 12:14:41
(3 weeks ago)
213.254.175.78 - - [25/Aug/2026:14:14:40 +0200] "GET /wp-login.php HTTP/1.1" 404 381 "-" "Mozilla/5. ...
show more
213.254.175.78 - - [25/Aug/2026:14:14:40 +0200] "GET /wp-login.php HTTP/1.1" 404 381 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
...
show less
Web App Attack
🇦🇺
screwlooseit.com.au
2026-07-13 03:50:45
(2 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
GB/United Kingdom/-
Web App Attack
🇺🇸
ipblock.com
2026-07-02 14:11:00
(2 months ago)
IPBlock protected site ID [4055-d][s=03].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇧🇷
dominioz
2026-05-24 10:47:52
(3 months ago)
2026-05-24 10:47:28 GET /b2c - - 213.254.175.78 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/53 ...
show more
2026-05-24 10:47:28 GET /b2c - - 213.254.175.78 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:29 GET /bug - - 213.254.175.78 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:30 GET /cPanel - - 213.254.175.78 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
2026-05-24 10:47:30 GET /calc - - 213.254.175.78 HTTP/1.1 Mozilla/5.0+(Windows+NT+x64)+AppleWebKit/537.36 - 404 104631
...
show less
Web App Attack
Anonymous
2026-05-03 17:49:11
(4 months ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇯🇵
demonsword
2026-04-28 15:53:57
(4 months ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: api.ipvanish.com:443
show less
Open Proxy
Port Scan
🇸🇬
aloon78
2026-04-02 00:00:00
(5 months ago)
WordPress xmlrpc.php brute force/exploit attempt on trillactive.com
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-03-28 23:33:05
(5 months ago)
1.171 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
🇺🇸
mnsf
2026-03-28 18:05:13
(5 months ago)
Too many Status 40X (18)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-03-16 19:13:31
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 213.254.175.78 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 213.254.175.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 15:13:26.875070 2026] [security2:error] [pid 26886:tid 26886] [client 213.254.175.78:42893] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 213.254.175.78 (+1 hits since last alert)|bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bernsteinip.com"] [uri "/xmlrpc.php"] [unique_id "abhWVup_HjywwtF4otuNVgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack