๐บ๐ธ
TPI-Abuse
2026-10-08 01:57:36
(6 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:57:33.332062 2026] [security2:error] [pid 7655:tid 7655] [client 104.23.166.179:9494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wedeliverstrippers.com"] [uri "/.env.old"] [unique_id "asb4jSF7QETE9Zr_K1V2yAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:27:02
(37 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:26:46.859871 2026] [security2:error] [pid 13365:tid 13365] [client 104.23.166.179:10913] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "majersigns.com"] [uri "/.git/HEAD"] [unique_id "asbxVknFaGxv_60RRgeq6QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 01:08:22
(56 minutes ago)
Sensitive Configuration File Disclosure.
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 01:06:10
(58 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:06:05.327349 2026] [security2:error] [pid 12705:tid 12730] [client 104.23.166.179:9620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailcleaner.com"] [uri "/.env.backup"] [unique_id "asbsfa6gQf43GEi0orUa2AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:41:47
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:41:37.540925 2026] [security2:error] [pid 24981:tid 25061] [client 104.23.166.179:12769] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "retrieversocal.com"] [uri "/.env.local"] [unique_id "asbYsVe1TMu_D4rSIsqreAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-07 23:40:23
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:17:32
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:17:27.952919 2026] [security2:error] [pid 1309:tid 1309] [client 104.23.166.179:13627] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mountainjaytherapy.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mountainjaytherapy.com"] [uri "/index.php.bak"] [unique_id "asbE93BszYQryJmLptztZAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:03:17
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:03:13.055984 2026] [security2:error] [pid 9065:tid 9065] [client 104.23.166.179:12373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primemanagementmn.com"] [uri "/.env.save"] [unique_id "asazkVzg-_MIa-Q8ZcxEFgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
p0tatosmash3r
2026-10-07 18:15:24
(7 hours ago)
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration ...
show more
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration.
show less
Web App Attack
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-10-07 18:08:03
(7 hours ago)
[07/Oct/2026:21:08:03 +0300] -- 104.23.166.179 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[07/Oct/2026:21:08:03 +0300] -- 104.23.166.179 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /wp-config.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 09:13:45
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:13:39.146452 2026] [security2:error] [pid 6285:tid 6285] [client 104.23.166.179:12527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelwakim.com"] [uri "/wp-config.php"] [unique_id "asYNQ3VrtyPgU_R7ocTiiAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-10-07 03:08:39
(22 hours ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1")
show less
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 02:54:25
(23 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:39:26
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:39:10.943503 2026] [security2:error] [pid 12368:tid 12368] [client 104.23.166.179:10200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evolutionmedical.help"] [uri "/wp-config.php"] [unique_id "asWwzniXPSS3bOMLEcFzYwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 01:49:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:48:58.927899 2026] [security2:error] [pid 5573:tid 5573] [client 104.23.166.179:9296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "megapct.com"] [uri "/wp-config.php.bak"] [unique_id "asWlChp6YG0JpJVfuv3e9AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack