๐บ๐ธ
TPI-Abuse
2026-09-29 23:14:44
(28 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:14:36.111648 2026] [security2:error] [pid 10139:tid 10139] [client 104.23.170.149:11328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glamorgirl.net"] [uri "/.env.staging"] [unique_id "arxGXLZkjf3RscqLl3Rw4AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:59:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:59:54.039217 2026] [security2:error] [pid 20280:tid 20280] [client 104.23.170.149:12064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.avrknives.com"] [uri "/.env.staging"] [unique_id "arwmyqLNDBrh-q6S4p7jRwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 19:52:43
(3 hours ago)
[29/Sep/2026:22:52:39 +0300] -- 104.23.170.149 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[29/Sep/2026:22:52:39 +0300] -- 104.23.170.149 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
lightaffaire
2026-09-29 19:08:07
(4 hours ago)
Sep 29 21:08:05 www.lightaffaire.com 104.23.170.149 - - [29/Sep/2026:21:08:05 +0200] "GET /.env.prod ...
show more
Sep 29 21:08:05 www.lightaffaire.com 104.23.170.149 - - [29/Sep/2026:21:08:05 +0200] "GET /.env.production HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 15:19:11
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 11:19:02.209942 2026] [security2:error] [pid 12896:tid 12896] [client 104.23.170.149:9574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "malinka.us"] [uri "/.env.backup"] [unique_id "arvW5vq2Rt-K2TL0jqPvkwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 01:00:44
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 21:00:39.666949 2026] [security2:error] [pid 9587:tid 9587] [client 104.23.170.149:10165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livinghopehighschool.org"] [uri "/wp-config.php.bak"] [unique_id "arsNt9FC_jnuVfkZo6zYqQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 21:00:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 17:00:05.889778 2026] [security2:error] [pid 7912:tid 7912] [client 104.23.170.149:10526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thewellnessxperience.com"] [uri "/.env.production"] [unique_id "arrVVXW-8uXaaUj67aMQOgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 17:04:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 13:04:11.106293 2026] [security2:error] [pid 19103:tid 19103] [client 104.23.170.149:11900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southernreader.com"] [uri "/.svn/entries"] [unique_id "arqeC-9YC33sgKL8lTtZxAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 10:18:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 06:18:52.178266 2026] [security2:error] [pid 19909:tid 19909] [client 104.23.170.149:10642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vexxarr.com"] [uri "/.env.local"] [unique_id "aro_DMRe3C2pACh2XLNIZwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-27 15:26:22
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-27 11:48:49
(2 days ago)
[27/Sep/2026:14:48:49 +0300] -- 104.23.170.149 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[27/Sep/2026:14:48:49 +0300] -- 104.23.170.149 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 14:00:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 10:00:48.232210 2026] [security2:error] [pid 5327:tid 5327] [client 104.23.170.149:12497] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oualierealty.com"] [uri "/.svn/entries"] [unique_id "arfQEIkTPLUYKZxHxatKDQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-26 10:19:31
(3 days ago)
[26/Sep/2026:13:19:30 +0300] -- 104.23.170.149 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[26/Sep/2026:13:19:30 +0300] -- 104.23.170.149 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-26 07:43:45
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-22 03:27:27
(1 week ago)
Persistent port scanning or vulnerability scanning
Port Scan