๐บ๐ธ
TPI-Abuse
2026-10-01 05:12:25
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:12:21.008781 2026] [security2:error] [pid 20511:tid 20511] [client 104.23.166.168:10522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "banis-associates.com"] [uri "/.env.production"] [unique_id "ar3rtUyDCEosGzXVbo9EJAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-30 18:55:23
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-30 15:26:59
(1 day ago)
[30/Sep/2026:18:26:59 +0300] -- 104.23.166.168 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[30/Sep/2026:18:26:59 +0300] -- 104.23.166.168 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐น๐ท
ScchutzZ
2026-09-30 15:05:09
(1 day ago)
Fail2Ban banฤฑ. Jail: plesk-modsecurity.
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 10:42:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:42:47.313929 2026] [security2:error] [pid 20507:tid 20507] [client 104.23.166.168:12199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conservadordehualpen.cl"] [uri "/.env.staging"] [unique_id "arznp9XK_QKtTZaQCREtqAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:05:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:05:11.632146 2026] [security2:error] [pid 9041:tid 9041] [client 104.23.166.168:12591] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "netpet.batw.net"] [uri "/.env.staging"] [unique_id "arze1wX0MkKVhAYrwkP72QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 06:04:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:04:54.086507 2026] [security2:error] [pid 5051:tid 5051] [client 104.23.166.168:10822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hteca.com"] [uri "/.git/config"] [unique_id "arymhkuIcIYfjR08IVq2pAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:04:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:04:33.123904 2026] [security2:error] [pid 28469:tid 28469] [client 104.23.166.168:13620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.10bestrealtors.com"] [uri "/.env.backup"] [unique_id "arxgIar3HkeVFP8K1th-nAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:18:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:18:04.661508 2026] [security2:error] [pid 32327:tid 32327] [client 104.23.166.168:13654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.peterndudar.com"] [uri "/.svn/entries"] [unique_id "arxVPF9q-RO2f1fwzdQ7QgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-09-30 00:08:49
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:15:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:15:21.674542 2026] [security2:error] [pid 23175:tid 23175] [client 104.23.166.168:9266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blackriverarc.org"] [uri "/.env.production"] [unique_id "arxGiappjQeOHO0Oymlw1QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 18:29:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:29:37.057129 2026] [security2:error] [pid 19352:tid 19352] [client 104.23.166.168:10384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.glendaleheritage.org"] [uri "/.env.staging"] [unique_id "arwDkXf_UYZKqFN_LHn2UQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 12:15:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:15:51.543621 2026] [security2:error] [pid 10148:tid 10161] [client 104.23.166.168:13916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "viasatsales.com"] [uri "/.env.staging"] [unique_id "arur9-78YZDL3fc2Uf8HbAAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-29 06:14:34
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 16:53:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 12:53:06.704938 2026] [security2:error] [pid 30245:tid 30245] [client 104.23.166.168:13443] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "franzexpress.com"] [uri "/.env.staging"] [unique_id "arqbcuLPQxQ_T170rvbc7gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack