๐บ๐ธ
TPI-Abuse
2026-10-05 23:19:30
(2 minutes ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 19:19:25.799883 2026] [security2:error] [pid 23720:tid 23720] [client 104.23.170.4:9823] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.achildsspace.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.achildsspace.com"] [uri "/index.php.bak"] [unique_id "asQwfagZl8Lr38mO15lEuQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 22:49:47
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:49:38.248626 2026] [security2:error] [pid 18324:tid 18324] [client 104.23.170.4:13963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horsesaw.com"] [uri "/wp-config.php.bak"] [unique_id "asQpgsw7KsLd7i8nRAQ7agAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 22:32:14
(49 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:32:09.092557 2026] [security2:error] [pid 17426:tid 17426] [client 104.23.170.4:11502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shawnlayne.com"] [uri "/.htaccess"] [unique_id "asQlaffHxB3D7FRFHo-GQAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 20:45:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 16:45:53.470662 2026] [security2:error] [pid 1210:tid 1210] [client 104.23.170.4:13628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rangerroma.com"] [uri "/.git/config"] [unique_id "asQMgdbdZN7El9xaZQpaywAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 20:29:15
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 16:29:06.369387 2026] [security2:error] [pid 32767:tid 327] [client 104.23.170.4:9473] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captainpurpleproductions.com"] [uri "/wp-config.php.save"] [unique_id "asQIkjfdMNGwsDa2dlirmAAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 09:29:48
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 05:29:43.834639 2026] [security2:error] [pid 27761:tid 27761] [client 104.23.170.4:11073] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||steveleeds.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "steveleeds.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asNuB4lPVqqBv3TBnh6nsQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Jochen Pretli
2026-10-05 04:39:12
(18 hours ago)
connection to honeypot
Email Spam
Port Scan
๐ฉ๐ช
baphomet
2026-10-03 10:45:52
(2 days ago)
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.e ...
show more
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.env/wp-login/xmlrpc/phpmyadmin/.git).
jail=nginx-canary proto=tcp port=80,443 failures>=2 class=web-app-probe
these paths are not real apps on this host; hit is hostile recon
when=2026-10-03T10:45:52Z sensor=fail2ban role=web-canary
src=104.23.170.4
show less
Web App Attack
๐ฉ๐ช
Holger
2026-10-02 08:29:54
(3 days ago)
WordPress WebAttack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:34:45
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:34:38.822471 2026] [security2:error] [pid 9068:tid 9068] [client 104.23.170.4:12591] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asiabeef.network"] [uri "/.env.production"] [unique_id "ar5FTnddNbGfMzXSsARLuAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-30 22:12:00
(5 days ago)
[01/Oct/2026:01:12:00 +0300] -- 104.23.170.4 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /w ...
show more
[01/Oct/2026:01:12:00 +0300] -- 104.23.170.4 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /wp-config.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:08:14
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:08:09.898955 2026] [security2:error] [pid 12179:tid 12179] [client 104.23.170.4:14018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "makenziereid.com"] [uri "/.git/config"] [unique_id "ar0XyWd6ekasKj1Ksh2sRQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:26:10
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:26:04.934210 2026] [security2:error] [pid 9901:tid 10070] [client 104.23.170.4:9678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whitecrosslibrary.com"] [uri "/.env.local"] [unique_id "arwQzHb1S3puNcQ6bcmz4QAAAco"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-29 18:22:33
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 13:18:15
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:18:10.647052 2026] [security2:error] [pid 2516:tid 2516] [client 104.23.170.4:13473] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wadenelson.com"] [uri "/.git/config"] [unique_id "aru6knxXgdS-TtpUu3SHuwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack