πΊπΈ
TPI-Abuse
2026-09-30 15:13:40
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:13:32.264215 2026] [security2:error] [pid 2388:tid 2483] [client 104.23.166.99:12039] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southtampaprints.com"] [uri "/.git/HEAD"] [unique_id "ar0nHDfABwykuiz0zp9CNAAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-30 07:38:21
(11 hours ago)
[30/Sep/2026:10:38:20 +0300] -- 104.23.166.99 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[30/Sep/2026:10:38:20 +0300] -- 104.23.166.99 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-09-30 07:05:27
(12 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 04:17:41
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:17:34.272400 2026] [security2:error] [pid 5666:tid 5666] [client 104.23.166.99:12076] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sifnosgreekcatering.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sifnosgreekcatering.com"] [uri "/index.php.bak"] [unique_id "aryNXiNwnrNjWmLiTXsUjAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 16:17:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 12:17:50.387536 2026] [security2:error] [pid 8469:tid 8469] [client 104.23.166.99:13077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amybeam.info"] [uri "/.env.production"] [unique_id "arvkrh7VtBwM3D--XaEIzgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 15:33:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 11:33:05.982802 2026] [security2:error] [pid 23744:tid 23768] [client 104.23.166.99:13699] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomas.kiehnefamily.us"] [uri "/.git/HEAD"] [unique_id "arvaMa0cn5dC4-PN_3ZJvAAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 13:26:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:26:32.544002 2026] [security2:error] [pid 16207:tid 16207] [client 104.23.166.99:11375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "birthplaceofprohockey.org"] [uri "/.env.local"] [unique_id "aru8iMLb1pWui91zZrV4zgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 12:43:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:43:18.693644 2026] [security2:error] [pid 15485:tid 15485] [client 104.23.166.99:9886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.appalachianstomp.com"] [uri "/.git/HEAD"] [unique_id "aruyZort4uJJrnZSzUMl2gAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
IRISIO
2026-09-29 06:59:51
(1 day ago)
scans/SQL injection/spam posts : 10 queries
Web App Attack
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-29 06:29:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 02:29:00.340809 2026] [security2:error] [pid 12453:tid 12465] [client 104.23.166.99:13905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.icecc.com"] [uri "/.env"] [unique_id "artarC5YcjW63Xs38Nz-kgAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
oja
2026-09-29 06:22:01
(1 day ago)
Aggressive web scanner
Web App Attack
π©πͺ
FeG Deutschland
2026-09-29 00:28:32
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-29 00:01:06
(1 day ago)
[29/Sep/2026:03:01:04 +0300] -- 104.23.166.99 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[29/Sep/2026:03:01:04 +0300] -- 104.23.166.99 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 20:15:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:15:34.908354 2026] [security2:error] [pid 8574:tid 8574] [client 104.23.166.99:10521] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accordionclub.org"] [uri "/.env.production"] [unique_id "arrK5lSc-fiBBZG-RSuGlgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 19:00:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.166.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 15:00:45.545271 2026] [security2:error] [pid 14037:tid 14037] [client 104.23.166.99:11001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "professionalpartyplanner.org"] [uri "/.git/config"] [unique_id "arq5XS3hGwOC3qxQj3-_3AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack