๐ฉ๐ช
Viveronese
2026-10-01 14:47:30
(3 hours ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-01 08:23:46
(9 hours ago)
[01/Oct/2026:11:23:45 +0300] -- 104.23.170.182 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[01/Oct/2026:11:23:45 +0300] -- 104.23.170.182 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 07:16:19
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 03:16:16.864135 2026] [security2:error] [pid 11766:tid 11842] [client 104.23.170.182:12669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "runawaydixie.com"] [uri "/.env.local"] [unique_id "ar4IwD5yFoPlr1Zo8i5NfQAAAgM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 04:02:06
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:01:58.831439 2026] [security2:error] [pid 12481:tid 12481] [client 104.23.170.182:13648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saadeh.ws"] [uri "/.env"] [unique_id "ar3bNoIU1UP-cNwUVehiXgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-01 00:15:14
(17 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mw
2026-10-01 00:01:23
(18 hours ago)
GET /wp-config.php.bak HTTP/1.1
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-30 23:00:36
(19 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
todix
2026-09-30 19:28:02
(22 hours ago)
Web App Attack Exploid from 104.23.170.182
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:05:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:05:38.325346 2026] [security2:error] [pid 24601:tid 24601] [client 104.23.170.182:13185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.portfolio.rnance.com"] [uri "/.svn/entries"] [unique_id "arztAnsfAHgvQqSPt_DW5QAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:19:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:19:04.725640 2026] [security2:error] [pid 9382:tid 9382] [client 104.23.170.182:9542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dianedanielsmanning.com"] [uri "/.env.staging"] [unique_id "arziGGNuie1kiprQHpdauAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:16:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:16:11.008439 2026] [security2:error] [pid 2386:tid 2522] [client 104.23.170.182:9467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.myrtlebeachdiet.com"] [uri "/.svn/entries"] [unique_id "arzTW3z5zw5Z8UrhJKT9dgAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 08:43:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 04:43:41.045011 2026] [security2:error] [pid 14933:tid 14933] [client 104.23.170.182:12982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daviddholt.com"] [uri "/wp-config.php.bak"] [unique_id "arzLvagckTiqv8nrG-HRKgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-30 03:00:28
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:44:21
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:44:14.488235 2026] [security2:error] [pid 21090:tid 21116] [client 104.23.170.182:12191] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||whatismetamodern.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "whatismetamodern.com"] [uri "/index.php.bak"] [unique_id "arxpbvaRMwdfGP80bvLVxwAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sorgin Informatique
2026-09-29 12:28:43
(2 days ago)
nee-21 : Rogue PHP files=>/config.php
Hacking