πΊπ¦
URAN Publishing Service
2026-10-03 05:59:07
(1 day ago)
[03/Oct/2026:08:59:07 +0300] -- 104.23.166.15 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[03/Oct/2026:08:59:07 +0300] -- 104.23.166.15 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 13:37:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:37:13.898568 2026] [security2:error] [pid 5630:tid 5674] [client 104.23.166.15:11340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icbc-canada.com"] [uri "/wp-config.php"] [unique_id "ar5iCVbHZwoBmQP-7rH8TAAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 12:18:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:18:05.166099 2026] [security2:error] [pid 26681:tid 26681] [client 104.23.166.15:10639] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.portraitsinblues.com"] [uri "/.git/config"] [unique_id "ar5Pffv2KZGUamKopAhmzwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 04:34:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:33:55.382138 2026] [security2:error] [pid 3509:tid 3509] [client 104.23.166.15:11045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "northfultonneurology.com"] [uri "/.env.backup"] [unique_id "ar3is7ki-yA-0ifwteZ5eAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Yosi
2026-09-30 15:30:35
(3 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-30 13:36:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:35:59.833367 2026] [security2:error] [pid 3231:tid 3231] [client 104.23.166.15:13959] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.centralbaptistalcoa.org"] [uri "/wp-config.php"] [unique_id "ar0QPxaqwidIPiR2_6rXDQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 10:10:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:10:24.025601 2026] [security2:error] [pid 28642:tid 28661] [client 104.23.166.15:9872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chelseyrae.com"] [uri "/.svn/entries"] [unique_id "arzgECA6np7rSj97Z_hB7QAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-30 02:53:11
(4 days ago)
[30/Sep/2026:05:53:10 +0300] -- 104.23.166.15 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[30/Sep/2026:05:53:10 +0300] -- 104.23.166.15 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-09-29 20:18:12
(4 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 17:57:14
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:57:11.195454 2026] [security2:error] [pid 9029:tid 9036] [client 104.23.166.15:11914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.a2zlns.com"] [uri "/.svn/entries"] [unique_id "arv796OE9UcZOa63xDQANQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 16:42:42
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 12:42:13.348619 2026] [security2:error] [pid 19432:tid 19432] [client 104.23.166.15:12085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.africanwisdominimageandproverb.com"] [uri "/.env.backup"] [unique_id "arvqZdqpvDF6ENUvpWERHAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Lee Daniel
2026-09-29 09:49:55
(4 days ago)
104.23.166.15 - - [29/Sep/2026:05:49:55 -0400] "GET /.htaccess HTTP/1.1" 403 377 "-" "Mozilla/5.0 (W ...
show more
104.23.166.15 - - [29/Sep/2026:05:49:55 -0400] "GET /.htaccess HTTP/1.1" 403 377 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-09-29 03:36:52
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 18:16:19
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 14:16:11.805073 2026] [security2:error] [pid 23660:tid 23660] [client 104.23.166.15:12289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rnance.com"] [uri "/.env.production"] [unique_id "arqu63eGDxT4JH7mKAW-VgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 08:58:08
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 04:58:02.271038 2026] [security2:error] [pid 11210:tid 11210] [client 104.23.166.15:11215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nomanszone.org"] [uri "/.env.staging"] [unique_id "arosGsadssM9zrtRAsVodQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack