๐ซ๐ท
security.rdmc.fr
2026-10-10 02:00:52
(24 minutes ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 23:21:45
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 19:21:28.670832 2026] [security2:error] [pid 16852:tid 16852] [client 104.23.166.66:9554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spacebooger.com"] [uri "/wp-config.php"] [unique_id "asl2-I_byMIDDYdP958FeAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 21:34:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:34:48.367855 2026] [security2:error] [pid 22267:tid 22267] [client 104.23.166.66:12886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karenjoyce.com"] [uri "/.env.dev"] [unique_id "asld-A4C5zJ8awq5IakY3QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:59:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:59:35.568544 2026] [security2:error] [pid 10976:tid 10976] [client 104.23.166.66:13005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hollyndlaw.com"] [uri "/.env.dev"] [unique_id "aslHp9FJKcCTQJthBRhMrAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 15:34:43
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 11:34:32.075561 2026] [security2:error] [pid 1393:tid 1393] [client 104.23.166.66:11783] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||heathdiesel.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "heathdiesel.com"] [uri "/index.php.bak"] [unique_id "askJiCbL3boWTBSE1IjFLQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 10:37:14
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 06:37:09.343709 2026] [security2:error] [pid 32413:tid 32413] [client 104.23.166.66:12731] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kdarmsta.com"] [uri "/.git/config"] [unique_id "asjD1aqtd3JJjLAb_vOBEAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
JuansaDigital
2026-10-09 08:44:45
(17 hours ago)
Security & Audit Shield Wordpress report: WAF attack signature: /.ssh
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 02:33:11
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:33:08.331644 2026] [security2:error] [pid 7431:tid 7431] [client 104.23.166.66:12908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peggyannjones.us"] [uri "/.env.production"] [unique_id "ashSZOFstJs5MIPrav2FywAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:45:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:45:51.359809 2026] [security2:error] [pid 3862:tid 3862] [client 104.23.166.66:11961] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riedmannfamily.com"] [uri "/.env.save"] [unique_id "ashHT3eEFo9bqqgN9YdeAwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:26:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:26:01.156248 2026] [security2:error] [pid 18304:tid 18304] [client 104.23.166.66:9689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nedelam.com"] [uri "/wp-config.php.save"] [unique_id "ashCqZ26PE0_tGOsu1HdQQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-08 18:51:05
(1 day ago)
104.23.166.66 - - [08/Oct/2026:18:50:29 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 34435 "-" "Mo ...
show more
104.23.166.66 - - [08/Oct/2026:18:50:29 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 34435 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "34.7.99.97" edge="104.23.166.66"
104.23.166.66 - - [08/Oct/2026:18:50:30 +0000] "GET /.npmrc HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "34.7.99.97" edge="104.23.166.66"
104.23.166.66 - - [08/Oct/2026:18:50:30 +0000] "GET /.htpasswd HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "34.7.99.97" edge="104.23.166.66"
104.23.166.66 - - [08/Oct/2026:18:50:31 +0000] "GET /.ssh/id_rsa HTTP/2.0" 403 34433 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "34.7.99.97" edge="104.23.166.66"
104.23.166.66 - - [08/Oct/2026:18:50:31 +0000] "GET /.ssh/id_ed25519 HTTP/2.0" 403 34433 "-" "M
...
show less
Web App Attack
๐ฉ๐ช
4server
2026-10-08 11:42:26
(1 day ago)
[ThuOct0813:42:19.9747352026][security2:error][pid2307335:tid2307405][client104.23.166.66:0]ModSecur ...
show more
[ThuOct0813:42:19.9747352026][security2:error][pid2307335:tid2307405][client104.23.166.66:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"feldenkraisticino.ch\"][uri\"/.docker/config.json\"][unique_id\"aseBm3ra4-PSjbJGd4I_dgAAAYk\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-10-08 09:59:49
(1 day ago)
IP matched detection query many 3xx errors.
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-08 09:27:31
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:27:27.227179 2026] [security2:error] [pid 25774:tid 25774] [client 104.23.166.66:12105] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "789-bid.com"] [uri "/.env.local"] [unique_id "asdh_wCQnTo-0n1WCIyubgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:26:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:26:20.354659 2026] [security2:error] [pid 7211:tid 7211] [client 104.23.166.66:9485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bakerimaging.com"] [uri "/wp-config.php"] [unique_id "asdFnNoOZeOESi8vkyjHDgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack