Anonymous
2026-09-29 01:47:45
(1 hour ago)
Sensitive Configuration File Disclosure.
Hacking
πΊπΈ
TPI-Abuse
2026-09-29 01:30:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 21:30:15.418060 2026] [security2:error] [pid 7058:tid 7058] [client 104.23.166.154:11094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fattoria-rendena.it"] [uri "/.env.backup"] [unique_id "arsUpzT7m-BdXP3w0y2J0gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 00:40:10
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:40:02.536463 2026] [security2:error] [pid 27193:tid 27193] [client 104.23.166.154:12837] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyqci.eu"] [uri "/.env.backup"] [unique_id "arsI4mlhwH03uRtjG8e1JQAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-09-28 22:20:41
(4 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, aws_creds, git_exposure, ssh_keys, source_backup. Observed by 1 sensor(s); 14 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 21:53:10
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 17:53:05.777204 2026] [security2:error] [pid 30311:tid 30311] [client 104.23.166.154:13138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ironsightsarmory.com"] [uri "/.env.local"] [unique_id "arrhwdO7Ej0R2CFJxlx1WwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 20:23:49
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:23:42.569192 2026] [security2:error] [pid 409:tid 409] [client 104.23.166.154:12937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davesullivan.net"] [uri "/.svn/entries"] [unique_id "arrMzs--gf4YL_QMx85w1QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Vegascosmetics
2026-09-28 20:07:53
(7 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after admin/path reconnaissance / port-scan ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after admin/path reconnaissance / port-scan-like web scan. Evidence: AttackPattern: /admin/ (Match: /admin/)
show less
Port Scan
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 17:05:19
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 13:05:15.674892 2026] [security2:error] [pid 12252:tid 12252] [client 104.23.166.154:13677] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comments.barkdull.org"] [uri "/.env"] [unique_id "arqeSymqISyEjacc2V56vwAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 15:14:07
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 11:13:59.800307 2026] [security2:error] [pid 3256:tid 3256] [client 104.23.166.154:13514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "efgenios.com"] [uri "/.env.production"] [unique_id "arqEN9kLDfWTn7Mzat1SVAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 12:44:53
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 08:44:45.456770 2026] [security2:error] [pid 13756:tid 13756] [client 104.23.166.154:10471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.partybusdaytonabeach.com"] [uri "/.env.backup"] [unique_id "arphPQDV8fNEIlvf5uwoJQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 10:20:33
(16 hours ago)
Banned by Fail2Ban on server
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 08:56:46
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 04:56:42.136184 2026] [security2:error] [pid 23051:tid 23117] [client 104.23.166.154:13958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfinancialanalyst.org"] [uri "/.env.backup"] [unique_id "aroryqZ05VMFjhpBKpKi-gAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-09-28 08:14:15
(18 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-27 12:22:22
(1 day ago)
[27/Sep/2026:15:22:22 +0300] -- 104.23.166.154 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[27/Sep/2026:15:22:22 +0300] -- 104.23.166.154 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1
show less
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-09-26 13:29:06
(2 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack