🇺🇸
TPI-Abuse
2026-10-06 23:06:32
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:06:17.980878 2026] [security2:error] [pid 23681:tid 23681] [client 104.23.166.134:9285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alsetsystems.com"] [uri "/wp-config.php"] [unique_id "asV-6c6T1YS1is2KB31pDAAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-10-06 16:33:49
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:33:41.199108 2026] [security2:error] [pid 12346:tid 12346] [client 104.23.166.134:11759] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lkabookeeping.com"] [uri "/.env.bak"] [unique_id "asUi5a490omGd3PYRIFuvgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-10-06 15:28:23
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:28:17.731000 2026] [security2:error] [pid 27456:tid 27456] [client 104.23.166.134:12498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vittariacapital.com"] [uri "/wp-config.php.bak"] [unique_id "asUTkTUBU8PDR9DehHBbYAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nationaleventpros.com
2026-10-06 15:18:04
(15 hours ago)
vulnerability scan
Web App Attack
🇺🇸
TPI-Abuse
2026-10-06 13:41:00
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:40:53.712453 2026] [security2:error] [pid 13163:tid 13172] [client 104.23.166.134:10669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taxelon.com"] [uri "/.env.staging"] [unique_id "asT6ZbwhdUrJVhFCsPB15AAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-10-06 13:10:14
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:10:04.092278 2026] [security2:error] [pid 24885:tid 24885] [client 104.23.166.134:13109] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tell-me-first.com"] [uri "/.env.backup"] [unique_id "asTzLNHzQW__0zjjGvuPDgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-10-06 12:14:57
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:14:47.076715 2026] [security2:error] [pid 7556:tid 7556] [client 104.23.166.134:9615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffreyasweeney.com"] [uri "/.env"] [unique_id "asTmN9F4Q034R2U5P3GVOgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-10-06 06:09:16
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 02:09:08.141959 2026] [security2:error] [pid 1344543:tid 1344562] [client 104.23.166.134:14154] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||isoceansl.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "isoceansl.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asSQhEa5PCLz01s2DjnpUQAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-10-06 02:58:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 22:58:44.015106 2026] [security2:error] [pid 1041:tid 1041] [client 104.23.166.134:10348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.achildsspace.com"] [uri "/.env.dev"] [unique_id "asRj5Ax2oySJI_Y2bGl36AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-10-05 21:29:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:29:29.877358 2026] [security2:error] [pid 31470:tid 31470] [client 104.23.166.134:9598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jtagulator.com"] [uri "/.env.production"] [unique_id "asQWuQZt9LMdkPt2UMDQUAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
borbolla
2026-10-04 04:26:25
(3 days ago)
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /wp-admin/install.php?step ...
show more
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /wp-admin/install.php?step=1 HTTP/2.0"
show less
Web App Attack
Bad Web Bot
🇹🇷
crnpekgoz
2026-10-03 17:17:07
(3 days ago)
Malicious HTTP GET request for '/.env.php' (HTTP 404) from 104.23.166.134. Threat: Web Güvenlik Açığ ...
show more
Malicious HTTP GET request for '/.env.php' (HTTP 404) from 104.23.166.134. Threat: Web Güvenlik Açığı Taraması (.env/bot). Blocked by WardenGuard Web Shield.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-10-01 14:49:49
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:49:46.141149 2026] [security2:error] [pid 17803:tid 17803] [client 104.23.166.134:13097] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.truthsabouthealthcare.com"] [uri "/.htaccess"] [unique_id "ar5zCuH1UVjHNYAKKHsJcQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
crnpekgoz
2026-10-01 14:05:50
(5 days ago)
Malicious HTTP GET request for '/.env' (HTTP 404) from 104.23.166.134. Threat: Web Güvenlik Açığı Ta ...
show more
Malicious HTTP GET request for '/.env' (HTTP 404) from 104.23.166.134. Threat: Web Güvenlik Açığı Taraması (.env/bot). Blocked by WardenGuard Web Shield.
show less
Web App Attack
🇺🇦
URAN Publishing Service
2026-10-01 12:03:46
(5 days ago)
[01/Oct/2026:15:03:45 +0300] -- 104.23.166.134 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[01/Oct/2026:15:03:45 +0300] -- 104.23.166.134 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack