๐บ๐ธ
TPI-Abuse
2026-10-01 13:26:37
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:26:31.718639 2026] [security2:error] [pid 32023:tid 32023] [client 104.23.170.21:10350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whengarbotalks.com"] [uri "/.env.production"] [unique_id "ar5fh14NIt6qMw87giS88QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:33:05
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:33:00.231186 2026] [security2:error] [pid 13637:tid 13637] [client 104.23.170.21:13641] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||borzois.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "borzois.com"] [uri "/index.php.bak"] [unique_id "ar5S_KhrLTsXxMbwKFdXdAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 06:59:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:59:33.116257 2026] [security2:error] [pid 29860:tid 29860] [client 104.23.170.21:14195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexgitlin.com"] [uri "/.git/config"] [unique_id "ar4E1UHuGneMm4ifd-jlJgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Holger
2026-10-01 05:16:54
(13 hours ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-01 02:37:45
(15 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฎ๐น
Inartis
2026-09-30 22:32:44
(19 hours ago)
104.23.170.21 - - [01/Oct/2026:00:31:57 +0200] "GET /.env.staging HTTP/1.1" 403 5207 "-" "Mozilla/5. ...
show more
104.23.170.21 - - [01/Oct/2026:00:31:57 +0200] "GET /.env.staging HTTP/1.1" 403 5207 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
104.23.170.21 - - [01/Oct/2026:00:32:22 +0200] "GET /config.php HTTP/1.1" 403 5207 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
104.23.170.21 - - [01/Oct/2026:00:32:30 +0200] "GET /config.php HTTP/1.1" 403 5207 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-30 18:41:40
(23 hours ago)
[30/Sep/2026:21:41:39 +0300] -- 104.23.170.21 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[30/Sep/2026:21:41:39 +0300] -- 104.23.170.21 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.staging HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:26:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:26:10.819488 2026] [security2:error] [pid 31813:tid 31813] [client 104.23.170.21:9717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dmasoftlab.com"] [uri "/.svn/entries"] [unique_id "ar0cAu1F1XkejC9q-bUoBQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:05:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:05:18.622458 2026] [security2:error] [pid 17250:tid 17250] [client 104.23.170.21:13461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aupapierjaponais.com"] [uri "/.env.local"] [unique_id "arze3nghecm0xuJAyE0gEQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 08:24:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 04:24:20.337324 2026] [security2:error] [pid 9141:tid 9141] [client 104.23.170.21:11329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.livinghopehighschool.org"] [uri "/.env.local"] [unique_id "arzHNDwxAmKLYGte3SJHDgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Jacqb
2026-09-30 04:46:00
(1 day ago)
Adres potencjalnie niebezpieczny
Brute-Force
Web App Attack
Bad Web Bot
๐ง๐ช
voormedia
2026-09-30 00:00:55
(1 day ago)
Accessed trap at '/.git/HEAD'
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 16:28:46
(2 days ago)
[29/Sep/2026:19:28:45 +0300] -- 104.23.170.21 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[29/Sep/2026:19:28:45 +0300] -- 104.23.170.21 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-29 15:25:16
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 12:13:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:13:00.630661 2026] [security2:error] [pid 32638:tid 32638] [client 104.23.170.21:11348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cyprus-boat-registration.com"] [uri "/.env.backup"] [unique_id "arurTI6Udq0QyvUh2wvC8gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack