๐บ๐ธ
TPI-Abuse
2026-10-06 00:01:18
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 20:01:04.747627 2026] [security2:error] [pid 14023:tid 14023] [client 104.23.170.136:12492] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tribalpacifica.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tribalpacifica.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asQ6QNWo3gX5OaD1TkXTUwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 03:09:31
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 23:09:26.913630 2026] [security2:error] [pid 1667:tid 1667] [client 104.23.170.136:12201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "new-bethel-baptist-church.com"] [uri "/.env.backup"] [unique_id "asMU5mZRTakXI9y0c01VkgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 16:08:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 12:07:59.153461 2026] [security2:error] [pid 4190:tid 4235] [client 104.23.170.136:11353] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cityofmiddleton.org"] [uri "/.env.local"] [unique_id "asJ531spU9K7jSy9NbJI4QAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
ki3
2026-10-01 10:52:33
(4 days ago)
Fail2Ban: Web App Attacks and Forum Spam 104.23.170.136 1790851953.0(JST)
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:10:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:10:22.693270 2026] [security2:error] [pid 24565:tid 24565] [client 104.23.170.136:12404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dukemason.com"] [uri "/.env"] [unique_id "ar4xjsbDLHQUGLgK6lsKAAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-01 08:16:11
(4 days ago)
[01/Oct/2026:11:16:11 +0300] -- 104.23.170.136 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[01/Oct/2026:11:16:11 +0300] -- 104.23.170.136 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /index.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-01 08:06:44
(4 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐ซ๐ท
dynamix
2026-10-01 07:55:26
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 06:26:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:25:58.658522 2026] [security2:error] [pid 11954:tid 11954] [client 104.23.170.136:14071] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vrbsroma.com"] [uri "/.env.staging"] [unique_id "ar389q_sGPxwmkqysrtyRAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2026-10-01 06:00:23
(4 days ago)
Suspicious malicious activity
Hacking
Anonymous
2026-10-01 05:21:08
(4 days ago)
Banned by Fail2Ban on server
Web App Attack
๐ฎ๐น
Inartis
2026-10-01 02:45:55
(4 days ago)
104.23.170.136 - - [01/Oct/2026:04:45:54 +0200] "GET /.git/config HTTP/2.0" 403 112 "-" "Mozilla/5.0 ...
show more
104.23.170.136 - - [01/Oct/2026:04:45:54 +0200] "GET /.git/config HTTP/2.0" 403 112 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 01:59:48
(4 days ago)
104.23.170.136 - - [01/Oct/2026:03:59:47 +0200] "GET /.env HTTP/2.0" 403 166 "-" "Mozilla/5.0 (Windo ...
show more
104.23.170.136 - - [01/Oct/2026:03:59:47 +0200] "GET /.env HTTP/2.0" 403 166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-30 23:25:05
(5 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 18:21:53
(5 days ago)
Web App Attack