๐ฉ๐ช
raph
2026-10-11 10:49:45
(6 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-10-11 00:32:12
(16 hours ago)
AetherFox VoidGuard detected: [Sun Oct 11 00:32:02.505505 2026] [authz_core:error] [pid 2374639:tid ...
show more
AetherFox VoidGuard detected: [Sun Oct 11 00:32:02.505505 2026] [authz_core:error] [pid 2374639:tid 2374648] [client 104.23.166.28:12472] AH01630: client denied by server configuration: proxy:https://[MASKED]/.terraform/terraform.tfstate
[Sun Oct 11 00:32:09.652741 2026] [authz_core:error] [pid 2374640:tid 2374691] [client 104.23.166.28:13120] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Sun Oct 11 00:32:10.360875 2026] [authz_core:error] [pid 2374639:tid 2374651] [client 104.23.166.28:13124] AH01630: client denied by server configuration: proxy:http://[MASKED]/.kube/config
[Sun Oct 11 00:32:10.361046 2026] [authz_core:error] [pid 2374639:tid 2374651] [client 104.23.166.28:13124] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Sun Oct 11 00:32:11.565073 2026] [authz_core:error] [pid 2374640:tid 2374678] [client 104.23.166.28:13127] AH01630: client denied by server configuration: proxy:htt
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
gurnip
2026-10-10 23:52:58
(17 hours ago)
Vulnerability probe of page /.git/config, not found on the server.
Brute-Force
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-10 23:45:08
(17 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-10 23:12:40
(18 hours ago)
[11/Oct/2026:02:12:39 +0300] -- 104.23.166.28 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[11/Oct/2026:02:12:39 +0300] -- 104.23.166.28 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:13:48
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:13:39.641171 2026] [security2:error] [pid 16997:tid 16997] [client 104.23.166.28:11884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsprobabile.com"] [uri "/.git/config"] [unique_id "asq4kx5FxTTXrzqAzrcdtQAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
bohl-aiG5aef
2026-10-10 08:58:50
(1 day ago)
Suricata Alert [SID:2019526] ET WEB_SERVER WEB-PHP phpinfo access
Web App Attack
๐ง๐ท
vfAcceloReporter
2026-10-10 05:38:57
(1 day ago)
104.23.166.28 - - [10/Oct/2026:02:38:55 -0300] "GET /.env HTTP/2.0" 499 0 "-" "Mozilla/5.0 (Macintos ...
show more
104.23.166.28 - - [10/Oct/2026:02:38:55 -0300] "GET /.env HTTP/2.0" 499 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-10-09 22:28:21
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.23.166.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.166.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 18:28:17.706691 2026] [security2:error] [pid 29905:tid 29905] [client 104.23.166.28:13968] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tci.land|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tci.land"] [uri "/index.php.bak"] [unique_id "aslqgQeA2_1isGTwFrpNcQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
Gem
2026-10-09 22:08:01
(1 day ago)
Unauthorized web scan.
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-10-09 21:32:37
(1 day ago)
CMS/framework probe: 104.23.166.28 - - [09/Oct/2026:23:32:37 +0200] "GET /.env.old HTTP/1.1" 301 178 ...
show more
CMS/framework probe: 104.23.166.28 - - [09/Oct/2026:23:32:37 +0200] "GET /.env.old HTTP/1.1" 301 178 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1" asn=13335 org="Cloudflare, Inc." country=NL
...
show less
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-10-09 05:20:59
(2 days ago)
. Matched phrase "wp-config.php" at REQUEST_URI. (210492-srv1)
Web App Attack
๐จ๐ญ
backslash
2026-10-09 04:33:00
(2 days ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐ซ๐ท
dynamix
2026-10-09 00:15:44
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 08:04:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 04:03:55.397072 2026] [security2:error] [pid 30430:tid 30430] [client 104.23.166.28:11607] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waterjetsolutions.com"] [uri "/.git/HEAD"] [unique_id "asdOa1htrqmBIzJJMeQwfwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack