π©πͺ
ghostwarriors
2026-10-06 23:20:12
(1 hour ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π©πͺ
yitzhaq
2026-10-06 22:57:55
(1 hour ago)
104.23.170.46 - - [07/Oct/2026:00:57:53 +0200] "GET /wp-config.php.old HTTP/2.0" 404 0 "-" "Mozilla/ ...
show more
104.23.170.46 - - [07/Oct/2026:00:57:53 +0200] "GET /wp-config.php.old HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.170.46 - - [07/Oct/2026:00:57:53 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 404 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.170.46 - - [06/Oct/2026:23:23:14 +0200] "GET /%252f%252eaws%252fcredentials HTTP/1.1" 301 612 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
104.23.170.46 - - [06/Oct/2026:23:23:14 +0200] "GET /wp-config.php HTTP/1.1" 301 592 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
show less
Web App Attack
Brute-Force
πΊπΈ
TPI-Abuse
2026-10-06 16:07:51
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:07:25.128801 2026] [security2:error] [pid 23649:tid 23649] [client 104.23.170.46:9972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "usagreenrecycling.com"] [uri "/.env.staging"] [unique_id "asUcvdQMkjDWbBqV3WDDTQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 15:43:11
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:43:07.512153 2026] [security2:error] [pid 29101:tid 29101] [client 104.23.170.46:13535] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foundintranslation.net"] [uri "/.htaccess"] [unique_id "asUXC5biZEZcDCGLoiq11gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
altenglaner
2026-10-06 06:36:59
(17 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 23:42:32
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 19:42:20.863922 2026] [security2:error] [pid 30760:tid 30760] [client 104.23.170.46:9579] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brbcash.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brbcash.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asQ13DMZYgwEOhFe78ZRVwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 20:46:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 16:45:54.609371 2026] [security2:error] [pid 21998:tid 21998] [client 104.23.170.46:12939] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rangerroma.com"] [uri "/.git/HEAD"] [unique_id "asQMgim2Qn-kM-vd9_NCYgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-10-05 16:29:22
(1 day ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
Lee Daniel
2026-10-04 14:27:29
(2 days ago)
104.23.170.46 - - [04/Oct/2026:10:27:29 -0400] "GET /.htaccess HTTP/1.1" 403 377 "-" "Mozilla/5.0 (M ...
show more
104.23.170.46 - - [04/Oct/2026:10:27:29 -0400] "GET /.htaccess HTTP/1.1" 403 377 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-04 07:50:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 03:50:38.640129 2026] [security2:error] [pid 22980:tid 23010] [client 104.23.170.46:11965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captainpurpleproductions.com"] [uri "/.env"] [unique_id "asIFTlm-KImW3GJZYciZZAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-04 07:10:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 03:10:51.495522 2026] [security2:error] [pid 22943:tid 22943] [client 104.23.170.46:9525] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehomemailbox.com"] [uri "/.env.save"] [unique_id "asH7-_jL7AWQVd_aCzpxTAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-01 15:29:47
(5 days ago)
[01/Oct/2026:18:29:46 +0300] -- 104.23.170.46 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[01/Oct/2026:18:29:46 +0300] -- 104.23.170.46 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
π©πͺ
mxbl
2026-10-01 14:50:03
(5 days ago)
Scanning for CMS vulnerabilities on a non-CMS system: /.git/config
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 06:07:33
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:07:27.804862 2026] [security2:error] [pid 29595:tid 29595] [client 104.23.170.46:14158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rimaine.org"] [uri "/.env.production"] [unique_id "ar34nyO73EkctCsO9vHqRAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
DRI
2026-10-01 04:32:31
(5 days ago)
Web attack/Malicious activity detected
Web App Attack