๐บ๐ธ
TPI-Abuse
2026-10-09 00:03:22
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:03:15.847783 2026] [security2:error] [pid 1451:tid 1451] [client 104.23.166.113:9547] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garrisonfinancial.net"] [uri "/.git/HEAD"] [unique_id "asgvQ5kf7gvF8hyaP7WfYAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:32:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:32:00.777378 2026] [security2:error] [pid 32695:tid 32695] [client 104.23.166.113:12513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehiddengemmalta.com"] [uri "/.env.backup"] [unique_id "asgZ4P1fHkOiDP96Zu4nxgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 22:00:57
(4 hours ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-10-08 22:00:18
(4 hours ago)
Auto-ban: >3000 req/min op 2026-10-08
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 15:04:52
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 11:04:48.153145 2026] [security2:error] [pid 6590:tid 6590] [client 104.23.166.113:12460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.donutlocations.com"] [uri "/.env.local"] [unique_id "asexEA17v1Ti1sNWIh5LeAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 14:03:17
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:03:12.117247 2026] [security2:error] [pid 26260:tid 26267] [client 104.23.166.113:11853] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinglips.com"] [uri "/.svn/entries"] [unique_id "aseioHOKXjy8oqilpEo5tQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 10:17:58
(16 hours ago)
[08/Oct/2026:13:17:57 +0300] -- 104.23.166.113 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[08/Oct/2026:13:17:57 +0300] -- 104.23.166.113 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /credentials.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:58:22
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:58:19.957759 2026] [security2:error] [pid 26523:tid 26523] [client 104.23.166.113:13269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cozydesignae.com"] [uri "/.env.old"] [unique_id "asdNGyoRCcRENuOzj-HhmQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 06:43:01
(20 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 05:06:02
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 01:05:57.373129 2026] [security2:error] [pid 27390:tid 27390] [client 104.23.166.113:12856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.painting-with-numbers.com"] [uri "/.env.production"] [unique_id "ascktbqSZ7zIb0DOqFkeKgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:01:52
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:01:47.205246 2026] [security2:error] [pid 19275:tid 19275] [client 104.23.166.113:14005] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||captechtraining.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "captechtraining.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "ascVq9BhP64JHGBECsHCqQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 02:03:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 22:03:01.288779 2026] [security2:error] [pid 19585:tid 19585] [client 104.23.166.113:10468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "csme-eprr.com"] [uri "/wp-config.php.save"] [unique_id "asb51SJ0_ea4DK5_Yz1xGQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:32:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:32:02.971161 2026] [security2:error] [pid 21273:tid 21273] [client 104.23.166.113:11066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jennyfiore.com"] [uri "/wp-config.php.old"] [unique_id "asbIYiuQA5ESE5P4zZ-QygAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Roper123
2026-10-07 22:27:23
(1 day ago)
Web app exploits
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:50:09
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.166.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:50:01.192482 2026] [security2:error] [pid 26477:tid 26477] [client 104.23.166.113:9506] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tekrav.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tekrav.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asa-iZhpLelRI-AJ0exx6AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack