๐บ๐ธ
TPI-Abuse
2026-09-23 03:41:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 23:41:22.352623 2026] [security2:error] [pid 29513:tid 29513] [client 63.135.161.58:46081] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.73"] [uri "/wp-content/.env"] [unique_id "arNKYoQZaEMocmtRrexj_QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 03:04:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 23:04:39.780905 2026] [security2:error] [pid 911:tid 911] [client 63.135.161.58:63073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.98"] [uri "/crm/.env"] [unique_id "arNBx2Ma-BdbWmA5Ode7xQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 01:53:30
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:53:04.099008 2026] [security2:error] [pid 30630:tid 30630] [client 63.135.161.58:26121] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.116"] [uri "/admin/.env"] [unique_id "arMxAPSUS-lOSwI31Kv4YAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 01:07:20
(5 hours ago)
automatically banned
Brute-Force
Web App Attack
๐ญ๐บ
kollanyit
2026-09-23 00:51:35
(5 hours ago)
63.135.161.58 - - [23/Sep/2026:00:51:23 +0000] "GET /api/.env HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Wi ...
show more
63.135.161.58 - - [23/Sep/2026:00:51:23 +0000] "GET /api/.env HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 00:38:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:38:09.424538 2026] [security2:error] [pid 17165:tid 17194] [client 63.135.161.58:62447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.84"] [uri "/base/.env"] [unique_id "arMfcYut3xMIW9B-_kMwuQAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 23:35:48
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:35:37.994694 2026] [security2:error] [pid 28422:tid 28422] [client 63.135.161.58:56367] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.189"] [uri "/newsite/.env"] [unique_id "arMQyci6-RcrDmHUajHtuAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-22 22:33:10
(7 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:08:56
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:08:32.974139 2026] [security2:error] [pid 17304:tid 17304] [client 63.135.161.58:47761] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.217"] [uri "/library/.env"] [unique_id "arL8YCrDoEQ_MpNKzM3h4QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:14:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 63.135.161.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:14:36.673212 2026] [security2:error] [pid 13476:tid 13476] [client 63.135.161.58:46225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.237"] [uri "/storage/.env"] [unique_id "arLvvO9JGQtw1wJNMK4_JgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
aks4226
2026-09-19 22:15:19
(3 days ago)
Attacking common web applications. (n01)
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-15 15:57:54
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
dynamix
2026-09-04 02:31:06
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-04 02:20:24
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-04 02:17:09
(2 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack