๐ซ๐ท
dynamix
2026-10-01 16:46:37
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
Lee Daniel
2026-10-01 15:46:11
(1 day ago)
104.23.166.156 - - [01/Oct/2026:11:46:11 -0400] "GET /.env HTTP/1.1" 403 6355 "-" "Mozilla/5.0 (Maci ...
show more
104.23.166.156 - - [01/Oct/2026:11:46:11 -0400] "GET /.env HTTP/1.1" 403 6355 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:20:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:19:57.120191 2026] [security2:error] [pid 30583:tid 30583] [client 104.23.166.156:11482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blackoakprop.com"] [uri "/wp-config.php"] [unique_id "ar56HYy2DYxB-dZX0RFpSQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-10-01 14:46:27
(1 day ago)
104.23.166.156 - - [02/Oct/2026:00:00:19 +1000] "GET /.svn/entries HTTP/1.1" 404 995 "-" "Mozilla/5. ...
show more
104.23.166.156 - - [02/Oct/2026:00:00:19 +1000] "GET /.svn/entries HTTP/1.1" 404 995 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
104.23.166.156 - - [02/Oct/2026:00:01:07 +1000] "GET /.index.php.swp HTTP/1.1" 404 995 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.166.156 - - [02/Oct/2026:00:01:15 +1000] "GET /.index.php.swp HTTP/1.1" 404 995 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.166.156 - - [02/Oct/2026:00:45:21 +1000] "GET /.env.production HTTP/1.1" 404 995 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
104.23.166.156 - - [02/Oct/2026:00:46:10 +1000] "GET /phpinfo.php HTTP/1.1" 404 16 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 09:21:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:21:02.743074 2026] [security2:error] [pid 24683:tid 24704] [client 104.23.166.156:14033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "credit-card-cap.com"] [uri "/.svn/entries"] [unique_id "ar4l_sg5uDY4jLFg0AO2HAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 04:59:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:59:00.351935 2026] [security2:error] [pid 29023:tid 29023] [client 104.23.166.156:10640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.southernislands.com"] [uri "/.git/HEAD"] [unique_id "ar3olIXn6lWcWpI2oz2R5AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-01 03:32:41
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2026-10-01 03:05:15
(1 day ago)
Suspicious malicious activity
Hacking
๐ซ๐ท
dynamix
2026-09-30 15:57:48
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-30 15:13:50
(2 days ago)
[30/Sep/2026:18:13:49 +0300] -- 104.23.166.156 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[30/Sep/2026:18:13:49 +0300] -- 104.23.166.156 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /wp-config.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 15:06:39
(2 days ago)
Trapped by Fail2Ban: Too many login failures from 104.23.166.156
Brute-Force
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 12:55:39
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 104.23.166.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.166.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:55:32.668054 2026] [security2:error] [pid 2388:tid 2486] [client 104.23.166.156:11634] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ainavelas.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ainavelas.com"] [uri "/index.php.bak"] [unique_id "ar0GxDfABwykuiz0zp86-AAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 05:38:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:38:42.498701 2026] [security2:error] [pid 1221:tid 1221] [client 104.23.166.156:13233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aden.us"] [uri "/.env.local"] [unique_id "arygYqV7d52K2dH7PYzdjwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-09-30 05:15:32
(2 days ago)
Probing for .env file:
104.23.166.156 - - [30/Sep/2026:07:15:27 +0200] "GET /.env.local HTTP/2.0" 40 ...
show more
Probing for .env file:
104.23.166.156 - - [30/Sep/2026:07:15:27 +0200] "GET /.env.local HTTP/2.0" 403 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-29 22:04:32
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-iad5-2)
Hacking
Web App Attack