๐ซ๐ท
dynamix
2026-10-01 16:47:23
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฆ๐บ
aranguren.org
2026-10-01 14:01:16
(2 days ago)
104.23.166.13 - - [02/Oct/2026:00:00:11 +1000] "GET /.env HTTP/1.1" 404 995 "-" "Mozilla/5.0 (Window ...
show more
104.23.166.13 - - [02/Oct/2026:00:00:11 +1000] "GET /.env HTTP/1.1" 404 995 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
104.23.166.13 - - [02/Oct/2026:00:00:27 +1000] "GET /.npmrc HTTP/1.1" 404 995 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
104.23.166.13 - - [02/Oct/2026:00:00:43 +1000] "GET /wp-config.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.166.13 - - [02/Oct/2026:00:00:51 +1000] "GET /config.yml HTTP/1.1" 404 995 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
104.23.166.13 - - [02/Oct/2026:00:01:07 +1000] "GET /index.php.bak HTTP/1.1" 404 995 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, lik
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 05:56:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:56:05.230493 2026] [security2:error] [pid 30632:tid 30661] [client 104.23.166.13:12861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adprospb.com"] [uri "/.env.staging"] [unique_id "ar319X7iJIZ62k1jB06OlgAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 04:58:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:58:44.315925 2026] [security2:error] [pid 29027:tid 29027] [client 104.23.166.13:12787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.southernislands.com"] [uri "/.env.backup"] [unique_id "ar3ohNC2hi1JoajEhRMiugAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2026-10-01 03:05:35
(3 days ago)
Suspicious malicious activity
Hacking
Anonymous
2026-09-30 23:54:30
(3 days ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-30 15:54:01
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:53:54.017272 2026] [security2:error] [pid 30845:tid 30845] [client 104.23.166.13:11478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marxistphilosophy.org"] [uri "/.svn/entries"] [unique_id "ar0wkrTvv-nI5whrYMsHDwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:21:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:21:12.917118 2026] [security2:error] [pid 17445:tid 17445] [client 104.23.166.13:10667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.circleinthesquare.org"] [uri "/.env.backup"] [unique_id "arzwqIKPv80H-IMh1EsuGAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:05:41
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:05:35.797640 2026] [security2:error] [pid 844:tid 844] [client 104.23.166.13:10740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aim-controls.com"] [uri "/.env.production"] [unique_id "arzQ3zmHnV5g_hC1zIGpLAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 07:49:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:49:05.079573 2026] [security2:error] [pid 3473:tid 3473] [client 104.23.166.13:10139] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anbruswebdesign.com"] [uri "/.env.staging"] [unique_id "ary-8Q11Hoi-F5kIkVaYwAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-09-30 06:35:20
(4 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-29 22:04:32
(4 days ago)
Restricted File Access Attempt. Matched phrase ".npmrc" at REQUEST_FILENAME. (930130-iad5-2)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:54:29
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:54:23.354997 2026] [security2:error] [pid 12524:tid 12524] [client 104.23.166.13:10600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.method1.net"] [uri "/.env.local"] [unique_id "arwlfyCS-me0P3ISTtTBlAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 14:51:44
(4 days ago)
[29/Sep/2026:17:51:43 +0300] -- 104.23.166.13 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[29/Sep/2026:17:51:43 +0300] -- 104.23.166.13 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /credentials.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 05:32:45
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 01:32:37.523809 2026] [security2:error] [pid 17133:tid 17133] [client 104.23.166.13:13813] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kerrywood.com"] [uri "/.env.staging"] [unique_id "artNdVSYWZg8ZPhKSDN1LAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack