๐บ๐ฆ
URAN Publishing Service
2026-10-01 15:28:15
(10 hours ago)
[01/Oct/2026:18:28:15 +0300] -- 104.23.170.153 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[01/Oct/2026:18:28:15 +0300] -- 104.23.170.153 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:06:05
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:06:00.229887 2026] [security2:error] [pid 19583:tid 19583] [client 104.23.170.153:9527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lyounglaw.com"] [uri "/.env.backup"] [unique_id "ar5auP-d7IZ5BZiNIFEV5QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-01 10:13:24
(15 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 06:12:54
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:12:50.692609 2026] [security2:error] [pid 9201:tid 9201] [client 104.23.170.153:13286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "djbadger.com"] [uri "/.env.local"] [unique_id "ar354q0UQL-OTJ8MhHnBIgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-01 05:07:13
(21 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-01 03:29:12
(22 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 03:20:09
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:20:05.734269 2026] [security2:error] [pid 17060:tid 17060] [client 104.23.170.153:13149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobileonlinecasinos.co"] [uri "/.env"] [unique_id "ar3RZS7TzWIbNmIFEGIsywAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-01 02:45:14
(23 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ท
LoneRider
2026-09-30 19:15:28
(1 day ago)
[30/Sep/2026:21:14:39.519874 +0200] ar1fn1bR85zGvASou84xigAAAAc 104.23.170.153 51446 127.0.0.1 7081
...
show more
[30/Sep/2026:21:14:39.519874 +0200] ar1fn1bR85zGvASou84xigAAAAc 104.23.170.153 51446 127.0.0.1 7081
[30/Sep/2026:21:14:47.353798 +0200] ar1fpwg4Oe-S2yEPf_pFWwAAAAE 104.23.170.153 43534 127.0.0.1 7081
[30/Sep/2026:21:15:27.776850 +0200] ar1fz9D-3gGWjCl8kFTQrAAAAAI 104.23.170.153 36552 127.0.0.1 7081
...
show less
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-09-30 13:50:52
(1 day ago)
[30/Sep/2026:16:50:52 +0300] -- 104.23.170.153 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[30/Sep/2026:16:50:52 +0300] -- 104.23.170.153 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-30 11:00:53
(1 day ago)
Active Response: IP 104.23.170.153 Blocked via Firewall Drop. Threat Score: 3.9/10 (LOW). Confidence ...
show more
Active Response: IP 104.23.170.153 Blocked via Firewall Drop. Threat Score: 3.9/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:55:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:54:59.252135 2026] [security2:error] [pid 7149:tid 7264] [client 104.23.170.153:12055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arthansl.com"] [uri "/.git/config"] [unique_id "arxd4z2NmvXNz5HXrK2BigAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:12:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:12:46.862488 2026] [security2:error] [pid 7843:tid 7843] [client 104.23.170.153:12898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nlc-calumet.org"] [uri "/.env.backup"] [unique_id "arxF7jT_H7ZE5wRCb-_uMQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-29 21:09:47
(2 days ago)
104.23.170.153 - - [29/Sep/2026:17:09:47 -0400] "GET /.aws/credentials HTTP/1.1" 404 6378 "-" "Mozil ...
show more
104.23.170.153 - - [29/Sep/2026:17:09:47 -0400] "GET /.aws/credentials HTTP/1.1" 404 6378 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 17:41:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:41:52.055152 2026] [security2:error] [pid 12735:tid 12735] [client 104.23.170.153:12223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teenybikinigirls.com"] [uri "/.env.local"] [unique_id "arv4YKmtjSDZxE6AqHTqVAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack