π©πͺ
raph
2026-10-11 02:28:07
(1 hour ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-10-11 02:08:07
(2 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-11 00:11:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:11:13.529345 2026] [security2:error] [pid 11808:tid 11808] [client 104.23.170.176:14041] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrsreclamation.com"] [uri "/.env.bak"] [unique_id "asrUIbnxuMhs_xosRJ_Z5wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-10-10 19:17:08
(8 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
π«π·
dynamix
2026-10-10 15:59:54
(12 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-10-10 07:09:33
(21 hours ago)
2026/10/10 07:09:30 [error] 3693533#3693533: *181712 [client 104.23.170.176] ModSecurity: Access den ...
show more
2026/10/10 07:09:30 [error] 3693533#3693533: *181712 [client 104.23.170.176] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.30.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "ussd2sms.ingeltechgh.com"] [uri "/.svn/entries"] [unique_id "17916161702.608580"] [ref ""], client: 104.23.170.176, server: srv.ingeltechgh.com, request: "GET /.svn/entries HTTP/2.0", host: "ussd2sms.ingeltechgh.com"
2026/10/10 07:09:30 [error] 3693532#3693532: *181711 [client 104.23.170.176] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value:
...
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-10-10 06:17:27
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 02:17:20.184680 2026] [security2:error] [pid 30951:tid 30951] [client 104.23.170.176:12669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darkalleyproductions.com"] [uri "/.git/HEAD"] [unique_id "asnYcDLAUvEBz25Hwdvy2gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§π·
vfAcceloReporter
2026-10-10 05:38:01
(22 hours ago)
104.23.170.176 - - [10/Oct/2026:02:38:00 -0300] "GET /.env.local HTTP/2.0" 499 0 "-" "Mozilla/5.0 (M ...
show more
104.23.170.176 - - [10/Oct/2026:02:38:00 -0300] "GET /.env.local HTTP/2.0" 499 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Exploited Host
πΊπΈ
TPI-Abuse
2026-10-10 00:29:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 20:29:53.110040 2026] [security2:error] [pid 32191:tid 32191] [client 104.23.170.176:13660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solidthought.com"] [uri "/wp-config.php.bak"] [unique_id "asmHAZXvOLImkYdtF6eojQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 23:42:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 19:41:59.040169 2026] [security2:error] [pid 12110:tid 12110] [client 104.23.170.176:12903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "konzel.com"] [uri "/.env.local"] [unique_id "asl7x1sV3LyRpJ2U16YQpAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Yosi
2026-10-09 20:09:46
(1 day ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
π¬π§
Smish
2026-10-09 09:41:12
(1 day ago)
HONEYPOT HIT --> Fail2ban time=1791538870 log=2026-10-09T10:41:10+01:00 ip=104.23.170.176 host=tpa-u ...
show more
HONEYPOT HIT --> Fail2ban time=1791538870 log=2026-10-09T10:41:10+01:00 ip=104.23.170.176 host=tpa-ultplus-04-game.bya.ac method=GET uri="/.env" status=404 ua="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" ref="-" rid=fe5f32a872c12f10865f37b4eabd494f
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 01:39:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:39:53.622191 2026] [security2:error] [pid 2366:tid 2366] [client 104.23.170.176:12552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "protonmultimedia.com"] [uri "/.env.dev"] [unique_id "ashF6XSjiUxHRj8m_ddUFgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mw
2026-10-09 00:03:17
(2 days ago)
GET /index.php.bak HTTP/1.1
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 18:56:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:56:14.485369 2026] [security2:error] [pid 14713:tid 14713] [client 104.23.170.176:11781] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianmindy.com"] [uri "/.env.bak"] [unique_id "asfnThJgYu6ITxFkColYwgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack