πΊπΈ
TPI-Abuse
2026-10-08 00:36:25
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:36:15.488708 2026] [security2:error] [pid 3057:tid 3057] [client 104.23.170.10:11192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spores101.com"] [uri "/.env"] [unique_id "asblf9ROjfR0s2YkdNvnCAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-10-08 00:19:57
(1 hour ago)
Multiple WAF Violations
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-07 23:53:31
(2 hours ago)
[08/Oct/2026:02:53:30 +0300] -- 104.23.170.10 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[08/Oct/2026:02:53:30 +0300] -- 104.23.170.10 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 23:26:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:26:25.470523 2026] [security2:error] [pid 8558:tid 8558] [client 104.23.170.10:10004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cruisingforsex.com"] [uri "/.env.staging"] [unique_id "asbVIVkYlNT9sa5hymJTLwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 22:01:36
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:01:30.633256 2026] [security2:error] [pid 3387:tid 3387] [client 104.23.170.10:12970] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deafinitely.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deafinitely.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asbBOu64APv8bE40nuCYcwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
on-com
2026-10-07 20:50:03
(5 hours ago)
URL scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 20:32:28
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:32:24.462108 2026] [security2:error] [pid 30977:tid 30977] [client 104.23.170.10:13562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mskimberleesspace.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mskimberleesspace.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asasWOSUwSBKymY6e8TcGgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Vegascosmetics
2026-10-07 18:35:41
(7 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 17:21:32
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 13:21:24.216730 2026] [security2:error] [pid 24981:tid 25054] [client 104.23.170.10:10260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boracayboats.com"] [uri "/.env.dev"] [unique_id "asZ_lFe1TMu_D4rSIsqTjQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 15:24:08
(10 hours ago)
104.23.170.10 - - [07/Oct/2026:12:24:07 -0300] "GET /index.php.bak HTTP/1.1" 404 1129 "-" "Mozilla/5 ...
show more
104.23.170.10 - - [07/Oct/2026:12:24:07 -0300] "GET /index.php.bak HTTP/1.1" 404 1129 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
...
show less
Port Scan
π©πͺ
altenglaner
2026-10-07 13:53:45
(12 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 13:27:15
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 09:27:08.480340 2026] [security2:error] [pid 18085:tid 18107] [client 104.23.170.10:12391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amphoracollectors.org"] [uri "/wp-config.php.save"] [unique_id "asZIrGOX11bbU823HgejZAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
Roper123
2026-10-07 13:00:08
(12 hours ago)
Web app exploits
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 10:30:17
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:30:08.497346 2026] [security2:error] [pid 18623:tid 18623] [client 104.23.170.10:10337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rodzillacharters.com"] [uri "/.env"] [unique_id "asYfMOXwykiZn9l60iFyTwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 06:43:01
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:42:58.041467 2026] [security2:error] [pid 26986:tid 26986] [client 104.23.170.10:12488] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.voodooshop.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.voodooshop.com"] [uri "/index.php.bak"] [unique_id "asXp8rghQlw2spUo-JBlLAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack