πΊπΈ
TPI-Abuse
2026-10-01 17:24:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:24:47.814541 2026] [security2:error] [pid 26851:tid 26939] [client 104.23.170.133:9968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.biblewriter.com"] [uri "/.env.local"] [unique_id "ar6XX3sRa9pGRKta8tDZpgAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 15:51:37
(2 days ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
π©πͺ
FD-IX
2026-10-01 14:32:29
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 10:17:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:17:52.672983 2026] [security2:error] [pid 11457:tid 11457] [client 104.23.170.133:12856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.greentirerecycling.com"] [uri "/.env.production"] [unique_id "ar4zUFK22_BSAtmEWKSsvwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-01 10:02:11
(2 days ago)
[01/Oct/2026:13:02:11 +0300] -- 104.23.170.133 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[01/Oct/2026:13:02:11 +0300] -- 104.23.170.133 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 05:31:10
(2 days ago)
GET /.env.local HTTP/1.1
...
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 15:51:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:51:46.283485 2026] [security2:error] [pid 4113:tid 4139] [client 104.23.170.133:12971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "docdalton.com"] [uri "/.env.local"] [unique_id "ar0wEqAgFLYPtxkaoUqtCAAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 13:00:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:00:41.256419 2026] [security2:error] [pid 16046:tid 16069] [client 104.23.170.133:10687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virtual411.com"] [uri "/.env"] [unique_id "ar0H-bQCfXQ_djdlMXCixwAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 12:08:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:08:15.403037 2026] [security2:error] [pid 13305:tid 13305] [client 104.23.170.133:11603] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lysedzija.com"] [uri "/.svn/entries"] [unique_id "arz7r0kBOZQSh2IdPgdEJwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
altenglaner
2026-09-30 10:05:59
(3 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 06:07:32
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:07:26.110619 2026] [security2:error] [pid 29868:tid 29868] [client 104.23.170.133:10808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gpaarch.com"] [uri "/.env.production"] [unique_id "arynHiA_Oid8S7o2JNaeVAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 05:50:40
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:50:35.475449 2026] [security2:error] [pid 1708:tid 1708] [client 104.23.170.133:9733] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crittergetterpestcontrol.com"] [uri "/.env.production"] [unique_id "aryjK209eJNF8pck9m3HSAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
www.elivecd.org
2026-09-29 22:31:38
(4 days ago)
104.23.170.133 - - [29/Sep/2026:23:31:06 +0100] "GET /phpinfo.php HTTP/2.0" 301 162 "-" "Mozilla/5.0 ...
show more
104.23.170.133 - - [29/Sep/2026:23:31:06 +0100] "GET /phpinfo.php HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.170.133 - - [29/Sep/2026:23:31:14 +0100] "GET /index.php.bak HTTP/2.0" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.170.133 - - [29/Sep/2026:23:31:14 +0100] "GET /phpinfo.php HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.170.133 - - [29/Sep/2026:23:31:21 +0100] "GET /index.php.bak HTTP/2.0" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.170.133 - - [29/Sep/2026:23:31:22 +0100] "GET /.index.php.swp HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0
...
show less
DDoS Attack
πΊπΈ
TPI-Abuse
2026-09-29 18:58:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:58:06.079855 2026] [security2:error] [pid 27897:tid 27897] [client 104.23.170.133:10833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.panama-boat-registration.com"] [uri "/.svn/entries"] [unique_id "arwKPlsl7f4dtg9bAqEnCgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ·
ScchutzZ
2026-09-29 14:05:17
(4 days ago)
Fail2Ban banΔ±. Jail: plesk-modsecurity.
Brute-Force