๐บ๐ธ
TPI-Abuse
2026-10-06 05:33:10
(14 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 01:33:01.886648 2026] [security2:error] [pid 30732:tid 30732] [client 104.23.170.34:11343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foundintranslation.net"] [uri "/.env"] [unique_id "asSIDYH89jaKzoxtzmSdTQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 00:27:08
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 20:27:03.209580 2026] [security2:error] [pid 19268:tid 19268] [client 104.23.170.34:11333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaleidoscope-glass.com"] [uri "/wp-config.php.old"] [unique_id "asRAVyiLIPPGg7eAqu46swAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 23:43:03
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 19:42:52.961354 2026] [security2:error] [pid 29227:tid 29234] [client 104.23.170.34:12616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rogamur.com"] [uri "/.env"] [unique_id "asQ1_OctxxOWhPQJzYxQqAAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-05 23:04:14
(6 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 22:34:18
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:34:07.345354 2026] [security2:error] [pid 18075:tid 18075] [client 104.23.170.34:12329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shawnlayne.com"] [uri "/.env.bak"] [unique_id "asQl35QM25Z4mVVkDRPpewAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 22:17:45
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:17:31.505783 2026] [security2:error] [pid 762:tid 762] [client 104.23.170.34:12157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||landjudging.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "landjudging.com"] [uri "/index.php.bak"] [unique_id "asQh-xcPLlh0lAPWdh8lJgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-05 17:11:06
(12 hours ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐ฉ
David Koswari
2026-10-05 05:21:00
(1 day ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
Anonymous
2026-10-04 08:10:53
(1 day ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 03:38:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 23:38:43.908718 2026] [security2:error] [pid 4370:tid 4370] [client 104.23.170.34:10584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "versahealthcare.com"] [uri "/.env"] [unique_id "asHKQ1ODlZvCjTpnkaTcywAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 08:33:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 04:33:46.002994 2026] [security2:error] [pid 16238:tid 16238] [client 104.23.170.34:13362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.evolute.io"] [uri "/.env.local"] [unique_id "ar4a6vjpsq3i25fxNmVtzwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-01 04:50:14
(5 days ago)
Multiple WAF Violations
Web App Attack
๐ช๐ธ
robotstxt
2026-10-01 03:14:06
(5 days ago)
104.23.170.34 - - [01/Oct/2026:03:13:36 +0000] "GET /.git/HEAD HTTP/2.0" 403 15391 "-" "Mozilla/5.0 ...
show more
104.23.170.34 - - [01/Oct/2026:03:13:36 +0000] "GET /.git/HEAD HTTP/2.0" 403 15391 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="104.23.170.34"
104.23.170.34 - - [01/Oct/2026:03:13:44 +0000] "GET /wp-config.php HTTP/2.0" 403 15391 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0" "2a06:98c0:3600::103" edge="104.23.170.34"
104.23.170.34 - - [01/Oct/2026:03:13:52 +0000] "GET /config.yml HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15" "2a06:98c0:3600::103" edge="104.23.170.34"
104.23.170.34 - - [01/Oct/2026:03:14:00 +0000] "GET /config.yaml HTTP/2.0" 403 15391 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="104.23.170.34"
104.23.170.34 - - [01/Oct/2026:03:14:00 +0000]
...
show less
Web App Attack
๐ฉ๐ช
raph
2026-10-01 03:07:51
(5 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-01 00:32:57
(5 days ago)
[01/Oct/2026:03:32:56 +0300] -- 104.23.170.34 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[01/Oct/2026:03:32:56 +0300] -- 104.23.170.34 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack