π«π·
IRISIO
2026-10-09 14:37:39
(49 minutes ago)
scans/SQL injection/spam posts : 26 queries
Web App Attack
SQL Injection
πΊπΈ
TPI-Abuse
2026-10-09 11:41:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 07:41:13.387904 2026] [security2:error] [pid 24592:tid 24592] [client 104.23.166.83:9262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grollman.com"] [uri "/.htaccess"] [unique_id "asjS2aVU06ZP-MmJt74irwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Petros Stefanakis
2026-10-09 08:56:22
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 104.23.166.83 (-)
SQL Injection
πΊπΈ
TPI-Abuse
2026-10-09 06:54:32
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 02:54:17.584624 2026] [security2:error] [pid 32597:tid 32597] [client 104.23.166.83:9990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blessedhavenfarm.com"] [uri "/.env.local"] [unique_id "asiPmRGArG_1-TRHi7rmKAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
taivas.nl
2026-10-08 21:32:11
(17 hours ago)
Bad_requests
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-08 18:37:35
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:37:28.175650 2026] [security2:error] [pid 15907:tid 15907] [client 104.23.166.83:11394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kadimasecurity.com"] [uri "/wp-config.php.bak"] [unique_id "asfi6Hw7Lb0rT8afqLmZGgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-10-08 08:58:19
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
π«π·
dynamix
2026-10-08 07:38:48
(1 day ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 06:58:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:58:01.681629 2026] [security2:error] [pid 3882:tid 3882] [client 104.23.166.83:12932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achari.com"] [uri "/.env.save"] [unique_id "asc--Ysf5ZQuAMVmdS1B_wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 04:45:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:45:45.387708 2026] [security2:error] [pid 10240:tid 10240] [client 104.23.166.83:11787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "htaautosales.com"] [uri "/.svn/entries"] [unique_id "ascf-XaA6aG1iqTsZYsn1wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
ISPLtd
2026-10-08 03:33:30
(1 day ago)
104.23.166.83 [08/Oct/2026:00:33:28 -0300] target.domain:80 URL:/wp-config.php.save "GET /wp-config. ...
show more
104.23.166.83 [08/Oct/2026:00:33:28 -0300] target.domain:80 URL:/wp-config.php.save "GET /wp-config.php.save
104.23.166.83 [08/Oct/2026:00:33:30 -0300] target.domain:80 URL:/.htaccess "GET /.htaccess
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 01:27:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:26:53.982064 2026] [security2:error] [pid 15315:tid 15315] [client 104.23.166.83:12947] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "majersigns.com"] [uri "/wp-config.php.bak"] [unique_id "asbxXcsEYOqV-YeWn8CdngAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
scaballe
2026-10-08 01:26:48
(1 day ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 01:06:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:06:05.419807 2026] [security2:error] [pid 12741:tid 12768] [client 104.23.166.83:9481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailcleaner.com"] [uri "/.env.local"] [unique_id "asbsfS1rnGYqPmSuxj-87gAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 00:48:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:48:49.378745 2026] [security2:error] [pid 12762:tid 12762] [client 104.23.166.83:10634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jfexpressfr8.com"] [uri "/.env.save"] [unique_id "asbocQ1bGegKAqlz52-80wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack