πΊπΈ
TPI-Abuse
2026-10-01 15:08:04
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:07:54.617740 2026] [security2:error] [pid 30690:tid 30690] [client 104.23.166.127:12087] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.batw.net"] [uri "/.env.production"] [unique_id "ar53Sj64zOsV15BCX64C2QAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 06:12:45
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:12:40.407449 2026] [security2:error] [pid 6362:tid 6362] [client 104.23.166.127:10687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primemanagementmn.com"] [uri "/.env.production"] [unique_id "ar352DJk9qjkPY6xk72kZgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-10-01 01:51:36
(16 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 00:59:46
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:59:41.449510 2026] [security2:error] [pid 3993:tid 3993] [client 104.23.166.127:13595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jackielangley.com"] [uri "/.env.staging"] [unique_id "ar2wfT6aiLAGKfv2MZMx1wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 20:36:22
(21 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-30 19:14:09
(22 hours ago)
[30/Sep/2026:22:14:08 +0300] -- 104.23.166.127 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[30/Sep/2026:22:14:08 +0300] -- 104.23.166.127 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 16:05:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:05:11.604969 2026] [security2:error] [pid 31653:tid 31653] [client 104.23.166.127:9522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barnesandbrower.com"] [uri "/.svn/entries"] [unique_id "ar0zN3_IK-JYi93J5NYn-gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:17:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:17:45.610869 2026] [security2:error] [pid 3933:tid 3933] [client 104.23.166.127:12764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sjtent.com"] [uri "/.env.production"] [unique_id "ar0oGagbqSLzxJi5SjBF_gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 14:25:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:25:21.290868 2026] [security2:error] [pid 12737:tid 12737] [client 104.23.166.127:10087] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.qualtacon.com"] [uri "/.svn/entries"] [unique_id "ar0b0QXHhMXHXDnHBGtlPgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 13:44:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:44:11.992255 2026] [security2:error] [pid 13884:tid 13896] [client 104.23.166.127:14242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.virtual411.com"] [uri "/.env.production"] [unique_id "ar0SK-UEF8A4tkXTQE_jYAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 10:56:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:56:15.275615 2026] [security2:error] [pid 25625:tid 25643] [client 104.23.166.127:14061] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.julianositalianrestaurant.com"] [uri "/.env.production"] [unique_id "arzqz0TyFob6tqikbBPsugAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-09-30 10:13:56
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: credentia ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: credential_file, aws_creds. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 10:08:03
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:07:55.244755 2026] [security2:error] [pid 21912:tid 21912] [client 104.23.166.127:10790] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hallemann.com"] [uri "/.env.local"] [unique_id "arzfeyOHU7N_HYMjyQJhfQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 06:55:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:55:47.230521 2026] [security2:error] [pid 10086:tid 10086] [client 104.23.166.127:10280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaleidoscope-glass.com"] [uri "/.svn/entries"] [unique_id "aryyc3r6HG3ZuzYTeIW3IwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Eldeberen
2026-09-30 05:02:21
(1 day ago)
Vulnerability scan attempt through HTTP protocol
Web App Attack