๐ฉ๐ช
FeG Deutschland
2026-10-08 08:58:14
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐จ๐ญ
zynex
2026-10-08 07:37:43
(2 hours ago)
URL Probing: /wp-config.php.save
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 07:05:02
(2 hours ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 104.23.166.106 - - [08/Oct/2026:09:04:45 +0200] "GET /.git/HEAD HTTP/1.1" 301 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:04:20
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:04:07.250250 2026] [security2:error] [pid 23150:tid 23150] [client 104.23.166.106:12807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dunnretired.com"] [uri "/.env.local"] [unique_id "ascWNyXVVVa47yzHAM-jXAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-08 02:06:20
(7 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:44:56
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:44:48.672203 2026] [security2:error] [pid 10344:tid 10344] [client 104.23.166.106:11856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keysenterprise.net"] [uri "/.env.production"] [unique_id "asbLYPvSgaQZs8DMFGq34QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
bohl-aiG5aef
2026-10-07 20:42:36
(13 hours ago)
Suricata Alert [SID:2031502] ET INFO Request to Hidden Environment File - Inbound
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-07 19:51:48
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:51:44.295713 2026] [security2:error] [pid 2478:tid 2478] [client 104.23.166.106:10585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.zezel.com"] [uri "/.git/HEAD"] [unique_id "asai0HuI10hqn4MCrJiGKAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 14:47:34
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 10:47:30.493826 2026] [security2:error] [pid 2333:tid 2333] [client 104.23.166.106:9566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "envirotreecare.com"] [uri "/wp-config.php.bak"] [unique_id "asZbgn6TyhwEAAuCsFN9xAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-07 10:13:09
(23 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 06:15:33
(1 day ago)
[07/Oct/2026:09:15:33 +0300] -- 104.23.166.106 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[07/Oct/2026:09:15:33 +0300] -- 104.23.166.106 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 03:18:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:18:47.167788 2026] [security2:error] [pid 26189:tid 26212] [client 104.23.166.106:9606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotairwelder.com"] [uri "/.htaccess"] [unique_id "asW6F8TPbK5yUswcEmMs9QAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:27:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:27:23.265350 2026] [security2:error] [pid 16368:tid 16368] [client 104.23.166.106:13350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greed.ee"] [uri "/.env.local"] [unique_id "asUha62JvOOAmYZsNrgkqgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:11:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:11:19.755684 2026] [security2:error] [pid 10333:tid 10333] [client 104.23.166.106:13395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "techamerica.net"] [uri "/.env.production"] [unique_id "asUPlzorqUt06Rhov-oCeQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:34:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:34:24.706376 2026] [security2:error] [pid 13071:tid 13071] [client 104.23.166.106:9297] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bikiniwatersports.com"] [uri "/.env.backup"] [unique_id "asUG8N5QInptanR_eQ_twwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack