๐บ๐ธ
TPI-Abuse
2026-09-29 10:34:56
(56 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:34:51.242732 2026] [security2:error] [pid 18869:tid 18869] [client 104.23.166.46:11202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lct.lbee.com"] [uri "/.env.production"] [unique_id "aruUS7lRypEGDjGD68IwhwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-29 08:56:26
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 00:00:57
(11 hours ago)
[29/Sep/2026:03:00:57 +0300] -- 104.23.166.46 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[29/Sep/2026:03:00:57 +0300] -- 104.23.166.46 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 18:23:52
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 14:23:47.226553 2026] [security2:error] [pid 14903:tid 14954] [client 104.23.166.46:12985] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "linfoulk.org"] [uri "/.env.production"] [unique_id "arqwsx6N5kMBHtZ_sSuajAAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 15:17:42
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 11:17:32.049214 2026] [security2:error] [pid 13332:tid 13332] [client 104.23.166.46:12320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-italy.com"] [uri "/.env"] [unique_id "arqFDNQSBIawg0YKN7dGKgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-09-28 14:55:47
(20 hours ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 09:23:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 05:23:48.215044 2026] [security2:error] [pid 8881:tid 8881] [client 104.23.166.46:12234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "etudesoftware.com"] [uri "/.env.staging"] [unique_id "aroyJAvmhaFPwefUMPLaWwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-26 18:59:43
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-26 13:30:08
(2 days ago)
GET /.env.staging HTTP/1.1
...
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-26 12:41:34
(2 days ago)
[26/Sep/2026:15:41:33 +0300] -- 104.23.166.46 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[26/Sep/2026:15:41:33 +0300] -- 104.23.166.46 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 11:33:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 07:33:03.621741 2026] [security2:error] [pid 6521:tid 6521] [client 104.23.166.46:10192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photoboutiqueamerica.com"] [uri "/.env.staging"] [unique_id "aretb9WjAjV0yaqP6TnScAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-26 11:30:15
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, credential_file. Observed by 1 sensor(s); 4 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 10:25:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 06:25:25.836083 2026] [security2:error] [pid 25855:tid 25924] [client 104.23.166.46:11054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gmentz.com"] [uri "/.env"] [unique_id "aredlew-v-3Ls9TZsnsRPAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 09:37:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 05:37:13.816685 2026] [security2:error] [pid 26769:tid 26769] [client 104.23.166.46:10533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlepeopledelivery.com"] [uri "/.env.backup"] [unique_id "areSSQEXD12b5fTy54NnqAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 08:49:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 04:49:00.967671 2026] [security2:error] [pid 21908:tid 21908] [client 104.23.166.46:10199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lakewoodranchhairsalon.com"] [uri "/.env.production"] [unique_id "areG_KrBaZ2DWNk2_YIcoQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack