πΊπΈ
TPI-Abuse
2026-10-10 23:45:52
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:45:48.919145 2026] [security2:error] [pid 26065:tid 26065] [client 104.23.170.154:9474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rcto.us"] [uri "/.env.old"] [unique_id "asrOLNs3whNpUI-b8GKv2QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 16:06:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 12:06:38.044119 2026] [security2:error] [pid 21705:tid 21705] [client 104.23.170.154:9309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tckgbookkeeping.biz"] [uri "/.env.staging"] [unique_id "askRDl_V-Z5EftFWJiufSwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 13:27:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 09:27:06.240030 2026] [security2:error] [pid 1277:tid 1277] [client 104.23.170.154:13448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.neff.family.name"] [uri "/.git/HEAD"] [unique_id "asjrqsv6mCBoR8ZOnfSW2QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Yosi
2026-10-09 04:21:46
(2 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
πΊπΈ
TPI-Abuse
2026-10-09 02:15:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:15:46.909063 2026] [security2:error] [pid 22281:tid 22281] [client 104.23.170.154:9405] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "puckerbottombikinis.com"] [uri "/wp-config.php.bak"] [unique_id "ashOUmenpWNEKXBbbLZiMgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 22:49:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:49:05.157896 2026] [security2:error] [pid 26506:tid 26521] [client 104.23.170.154:9625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newyorkfreepress.com"] [uri "/.git/config"] [unique_id "asgd4ff1BFvUHsWfFHJIJAAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 20:28:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:28:40.209596 2026] [security2:error] [pid 27144:tid 27144] [client 104.23.170.154:10985] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.donutlocations.com"] [uri "/.env.local"] [unique_id "asf8-MWZZ1XDUTBhmnwPjAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 13:59:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:59:05.637430 2026] [security2:error] [pid 6682:tid 6682] [client 104.23.170.154:13154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wendeenicole.com"] [uri "/.env.bak"] [unique_id "asehqbytFhvOAKj1us1INAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 04:44:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:43:57.707280 2026] [security2:error] [pid 27529:tid 27529] [client 104.23.170.154:10066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cnwire.com"] [uri "/.git/config"] [unique_id "ascfjcbrWnHM8uMbb8zpWQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 01:59:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:58:58.072579 2026] [security2:error] [pid 11239:tid 11239] [client 104.23.170.154:9291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "religiousholidaycards.com"] [uri "/wp-config.php.bak"] [unique_id "asb44q5Ss4ZVLdRSaaYt4gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 01:04:52
(3 days ago)
Sensitive Configuration File Disclosure.
Hacking
πΊπΈ
TPI-Abuse
2026-10-07 23:55:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:54:40.996067 2026] [security2:error] [pid 4865:tid 4865] [client 104.23.170.154:11308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "almudenastrust.com"] [uri "/.git/config"] [unique_id "asbbwEQfViELHIbqIcaW-wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 21:14:06
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:13:58.593078 2026] [security2:error] [pid 12682:tid 12682] [client 104.23.170.154:14270] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||evolutionmedical.help|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "evolutionmedical.help"] [uri "/index.php.bak"] [unique_id "asa2FvEyZK3oq06Cz8MfsgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 13:44:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 09:44:20.603722 2026] [security2:error] [pid 590:tid 590] [client 104.23.170.154:13726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelwakim.com"] [uri "/.env"] [unique_id "asZMtL4xNz-tSRbtSIHvCAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
craudiovizai
2026-10-07 06:30:37
(3 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot