๐ซ๐ท
dynamix
2026-10-08 00:18:52
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ญ๐บ
bcsaba
2026-10-08 00:05:17
(5 hours ago)
Suricata: Alert - ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:04:43
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:04:35.942476 2026] [security2:error] [pid 8347:tid 8347] [client 104.23.170.141:9268] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||majersigns.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "majersigns.com"] [uri "/index.php.bak"] [unique_id "asbQAxou5uBNPaUqGmXSdAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:38:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:38:49.481396 2026] [security2:error] [pid 17221:tid 17221] [client 104.23.170.141:11470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jennyfiore.com"] [uri "/wp-config.php.old"] [unique_id "asbJ-XoMG3206V2zd04rWgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 22:07:43
(7 hours ago)
[08/Oct/2026:01:07:42 +0300] -- 104.23.170.141 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[08/Oct/2026:01:07:42 +0300] -- 104.23.170.141 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /index.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:53:56
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:53:52.404949 2026] [security2:error] [pid 25985:tid 25985] [client 104.23.170.141:12981] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tekrav.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tekrav.com"] [uri "/index.php.bak"] [unique_id "asa_cMjvTJQL2odvFKW18gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:05:11
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:04:59.705284 2026] [security2:error] [pid 23098:tid 23098] [client 104.23.170.141:10573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swhowell.com"] [uri "/.env.old"] [unique_id "asaz-2ld6RFekHvfkmlTxwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-10-07 18:35:40
(11 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
p0tatosmash3r
2026-10-07 18:15:29
(11 hours ago)
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration ...
show more
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-07 02:28:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:28:25.586731 2026] [security2:error] [pid 3213504:tid 3213528] [client 104.23.170.141:12707] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aussiepens.com"] [uri "/.git/HEAD"] [unique_id "asWuSc0EDMNLsgnt6dPbzQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 01:30:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:30:50.076478 2026] [security2:error] [pid 23156:tid 23156] [client 104.23.170.141:11301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.lindenwoodpark.org"] [uri "/.env.old"] [unique_id "asWgys4hXtrnajAG6MM6wAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 00:43:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 20:42:59.079358 2026] [security2:error] [pid 9447:tid 9447] [client 104.23.170.141:13941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "belgiophar.com"] [uri "/.env.dev"] [unique_id "asWVk7R89ID8cV5wpCoSLQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 00:07:30
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:45:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:44:55.483032 2026] [security2:error] [pid 14632:tid 14632] [client 104.23.170.141:13620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "humbliaslaw.com"] [uri "/.env.backup"] [unique_id "asVr15bGXWq-UJIOVs3-7QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:11:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:11:29.915526 2026] [security2:error] [pid 19695:tid 19695] [client 104.23.170.141:11234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fancycleaners.com"] [uri "/.git/config"] [unique_id "asVkAfHH7YkjFYY4aFX9hQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack