๐น๐ท
ScchutzZ
2026-10-06 19:05:08
(2 hours ago)
Fail2Ban banฤฑ. Jail: plesk-modsecurity.
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-06 15:45:19
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:45:12.082167 2026] [security2:error] [pid 19102:tid 19102] [client 104.23.170.19:9363] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||disio.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "disio.com"] [uri "/index.php.bak"] [unique_id "asUXiCKKY_8-tJhr0OL7OQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ParaBug
2026-10-06 13:51:00
(7 hours ago)
104.23.170.19 - - [06/Oct/2026:15:50:59 +0200] "GET /.env.dev HTTP/2.0" 301 439 "-" "Mozilla/5.0 (X1 ...
show more
104.23.170.19 - - [06/Oct/2026:15:50:59 +0200] "GET /.env.dev HTTP/2.0" 301 439 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:32:54
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:32:45.463772 2026] [security2:error] [pid 29241:tid 29241] [client 104.23.170.19:13109] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.diamondtrailerserv.com"] [uri "/wp-config.php"] [unique_id "asT4fQLINfttnKjs--yRCwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:24:29
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:24:22.228324 2026] [security2:error] [pid 23238:tid 23238] [client 104.23.170.19:14228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tribalpacifica.com"] [uri "/wp-config.php.save"] [unique_id "asTodk4XI3qXkMiDk657NQAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:24:16
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:24:13.051000 2026] [security2:error] [pid 7454:tid 7486] [client 104.23.170.19:11050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jedelectric.com"] [uri "/.env.bak"] [unique_id "asTaXXvixbUNhveKwIz29wAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:27:07
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:27:01.257947 2026] [security2:error] [pid 16106:tid 16106] [client 104.23.170.19:13508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessiedavison.com"] [uri "/.env.old"] [unique_id "asTM9Wli_GMzohW0UPIqLwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 01:34:15
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 21:34:10.622543 2026] [security2:error] [pid 1275417:tid 1275443] [client 104.23.170.19:13906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "isoceansl.com"] [uri "/.env.backup"] [unique_id "asRQEi0mL98sHjhkVa7XXwAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
arsonist
2026-10-05 00:12:50
(1 day ago)
[fail2ban]
2026-10-05T00:12:49.496527+00:00 arson caddy[1712]: {"level":"info","ts":1791159169.49649 ...
show more
[fail2ban]
2026-10-05T00:12:49.496527+00:00 arson caddy[1712]: {"level":"info","ts":1791159169.4964972,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"104.23.170.19","remote_port":"11660","client_ip":"104.23.170.19","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??","headers":{"Cdn-Loop":["cloudflare; loops=1"],"Cf-Ipcountry":["NL"],"X-Forwarded-Proto":["https"],"X-Forwarded-For":["34.187.105.22"],"Accept-Encoding":["gzip, br"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"Accept":["*/*"],"User-Agent":["CCBot/2.0 (https://commoncrawl.org/faq/)"],"Cf-Connecting-Ip":["34.187.105.22"],"X-Nextjs-Data":["1"],"Cf-Ray":["
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-04 19:39:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 15:39:50.018886 2026] [security2:error] [pid 16194:tid 16194] [client 104.23.170.19:11160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brbcash.com"] [uri "/.env.old"] [unique_id "asKrhqL_uvXNhdrHAL4B-AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
ScchutzZ
2026-10-02 19:05:09
(4 days ago)
Fail2Ban banฤฑ. Jail: plesk-modsecurity.
Brute-Force
๐ฎ๐น
Inartis
2026-10-01 14:40:20
(5 days ago)
104.23.170.19 - - [01/Oct/2026:16:40:02 +0200] "GET /.env.local HTTP/1.1" 403 7606 "-" "Mozilla/5.0 ...
show more
104.23.170.19 - - [01/Oct/2026:16:40:02 +0200] "GET /.env.local HTTP/1.1" 403 7606 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.170.19 - - [01/Oct/2026:16:40:10 +0200] "GET /.git/config HTTP/1.1" 403 7606 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
104.23.170.19 - - [01/Oct/2026:16:40:19 +0200] "GET /.git/config HTTP/1.1" 403 7606 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-10-01 12:17:33
(5 days ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ฆ
URAN Publishing Service
2026-10-01 11:02:34
(5 days ago)
[01/Oct/2026:14:02:34 +0300] -- 104.23.170.19 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[01/Oct/2026:14:02:34 +0300] -- 104.23.170.19 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.staging HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 03:05:27
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:05:16.613954 2026] [security2:error] [pid 2870:tid 2870] [client 104.23.170.19:11599] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynthiabaxter.com"] [uri "/.env.staging"] [unique_id "ar3N7HZ11vP2WHxbzPI6YAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack