๐ฉ๐ช
raph
2026-09-29 20:18:21
(6 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-29 19:38:47
(7 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 17:41:01
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:40:54.567415 2026] [security2:error] [pid 2725:tid 2725] [client 104.23.166.64:11779] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ibeautyexchange.com"] [uri "/.env"] [unique_id "arv4Jsl8QBFxSGzhO9lLKAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-29 09:49:16
(17 hours ago)
104.23.166.64 - - [29/Sep/2026:05:49:16 -0400] "GET /.env HTTP/1.1" 403 344 "-" "Mozilla/5.0 (Window ...
show more
104.23.166.64 - - [29/Sep/2026:05:49:16 -0400] "GET /.env HTTP/1.1" 403 344 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 09:38:30
(17 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 05:35:30
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 01:35:23.397975 2026] [security2:error] [pid 7751:tid 7751] [client 104.23.166.64:13340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.appalachianfolkmagician.com"] [uri "/.git/HEAD"] [unique_id "artOGyGcpzZGgKhcE_5WtQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 02:27:04
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 02:23:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 22:23:22.300540 2026] [security2:error] [pid 4613:tid 4690] [client 104.23.166.64:10265] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chelseyrae.com"] [uri "/.env"] [unique_id "arshGr5-K7Gj5u9vsnOlNQAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 18:16:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 14:16:19.658889 2026] [security2:error] [pid 27154:tid 27154] [client 104.23.166.64:13358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rnance.com"] [uri "/.git/config"] [unique_id "arqu87_jGd_183_e3C7cuQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 17:24:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 13:24:38.656564 2026] [security2:error] [pid 12090:tid 12155] [client 104.23.166.64:12850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "financialanalyst.org"] [uri "/.git/config"] [unique_id "arqi1jgHs4y4BkI9e1nzQwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 15:47:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 11:47:33.853391 2026] [security2:error] [pid 5651:tid 5651] [client 104.23.166.64:11209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avanyupublishing.com"] [uri "/.env.production"] [unique_id "arqMFcaV8SARMOmMLoN7UwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-09-28 14:43:06
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-28 09:35:40
(1 day ago)
104.23.166.64 - - [28/Sep/2026:06:35:39 -0300] "GET /.git/config HTTP/1.1" 500 170 "-" "Mozilla/5.0 ...
show more
104.23.166.64 - - [28/Sep/2026:06:35:39 -0300] "GET /.git/config HTTP/1.1" 500 170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-28 08:58:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 04:58:02.276228 2026] [security2:error] [pid 11217:tid 11217] [client 104.23.166.64:11011] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nomanszone.org"] [uri "/.env.local"] [unique_id "arosGnxjJUHlG2FLRUMQugAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-27 22:21:15
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking