๐บ๐ธ
TPI-Abuse
2026-09-30 13:00:55
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:00:49.168362 2026] [security2:error] [pid 16046:tid 16073] [client 104.23.170.14:11638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virtual411.com"] [uri "/.svn/entries"] [unique_id "ar0IAbQCfXQ_djdlMXCizwAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:08:02
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:07:51.154846 2026] [security2:error] [pid 11639:tid 11639] [client 104.23.170.14:11393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lysedzija.com"] [uri "/.env.staging"] [unique_id "arz7l3KyQqrXanMPS6PCdwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-09-30 10:05:59
(4 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-30 10:03:36
(4 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-30 09:13:23
(5 hours ago)
[30/Sep/2026:12:13:22 +0300] -- 104.23.170.14 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[30/Sep/2026:12:13:22 +0300] -- 104.23.170.14 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:40:27
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:40:21.365261 2026] [security2:error] [pid 7364:tid 7364] [client 104.23.170.14:11792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jacob.bluegrassexpressband.com"] [uri "/.env.staging"] [unique_id "arxadX6lKiEJqUSfG7yKzwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 00:26:42
(14 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฌ๐ง
www.elivecd.org
2026-09-29 22:31:38
(16 hours ago)
104.23.170.14 - - [29/Sep/2026:23:30:50 +0100] "GET /config.php HTTP/2.0" 301 162 "-" "Mozilla/5.0 ( ...
show more
104.23.170.14 - - [29/Sep/2026:23:30:50 +0100] "GET /config.php HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
104.23.170.14 - - [29/Sep/2026:23:30:58 +0100] "GET /wp-config.php.bak HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
104.23.170.14 - - [29/Sep/2026:23:31:14 +0100] "GET /index.php~ HTTP/2.0" 301 162 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
104.23.170.14 - - [29/Sep/2026:23:31:21 +0100] "GET /index.php~ HTTP/2.0" 301 162 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
104.23.170.14 - - [29/Sep/2026:23:31:22 +0100] "GET /index.php.save HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101
...
show less
DDoS Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-29 21:59:49
(16 hours ago)
Auto-ban: >3000 req/min op 2026-09-29
Web App Attack
SSH
Hacking
๐ฎ๐ฉ
penjaga BRIN
2026-09-29 19:16:24
(19 hours ago)
Suspicious malicious activity
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-29 18:58:19
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:58:14.009136 2026] [security2:error] [pid 3673:tid 3673] [client 104.23.170.14:10370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.panama-boat-registration.com"] [uri "/wp-config.php"] [unique_id "arwKRpmVT2Hw1VxwJJIUyAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 10:47:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:47:15.384407 2026] [security2:error] [pid 13341:tid 13341] [client 104.23.170.14:11343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "closedfortheseason.com"] [uri "/.git/config"] [unique_id "aruXM-l9qrYlglKUrB6DAgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 05:25:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 01:25:30.249468 2026] [security2:error] [pid 884:tid 884] [client 104.23.170.14:13582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sigrc.org"] [uri "/.env"] [unique_id "artLyqLBYB_i_0F-C4ohOQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 03:31:44
(1 day ago)
[29/Sep/2026:06:31:43 +0300] -- 104.23.170.14 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[29/Sep/2026:06:31:43 +0300] -- 104.23.170.14 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 23:13:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 19:13:14.118646 2026] [security2:error] [pid 6350:tid 6350] [client 104.23.170.14:11992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.10mostwantedfugitives.com"] [uri "/.env"] [unique_id "arr0inBZ-pzSGWOEF2KyCwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack