๐บ๐ธ
TPI-Abuse
2026-09-30 13:04:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:04:11.313805 2026] [security2:error] [pid 5160:tid 5160] [client 104.23.170.6:10509] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ironsightsarmory.com"] [uri "/.env.local"] [unique_id "ar0Iy9K6DRLOFkOs4_SOAQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:13:10
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:13:04.871978 2026] [security2:error] [pid 23333:tid 23333] [client 104.23.170.6:13591] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.belize-boat-registration.com"] [uri "/.env"] [unique_id "arz80HKS9YsPnlpdx4LKSwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:54:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:54:02.861234 2026] [security2:error] [pid 19102:tid 19102] [client 104.23.170.6:11140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slattery-law.com"] [uri "/.env.local"] [unique_id "arz4Wh0oebPOY_-TRUZJHwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 07:33:24
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:33:20.044740 2026] [security2:error] [pid 3928:tid 3928] [client 104.23.170.6:10568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.lindenwoodpark.org"] [uri "/.env"] [unique_id "ary7QDQlsIWz9xbn5kilmgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 07:08:49
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:08:42.735820 2026] [security2:error] [pid 6571:tid 6571] [client 104.23.170.6:14213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.4photogifts.com"] [uri "/.git/config"] [unique_id "ary1epyH_3tA-sBKF1kPZAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
WebNiraj
2026-09-30 06:53:12
(9 hours ago)
(mod_security) mod_security (id:949110) triggered by 104.23.170.6 (NL/The Netherlands/-): 5 in the l ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.170.6 (NL/The Netherlands/-): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-30 03:50:24
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:50:18.268848 2026] [security2:error] [pid 19739:tid 19739] [client 104.23.170.6:12952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.konahawaii.com"] [uri "/.env.backup"] [unique_id "aryG-kw7ydpI-VS6gjJAvwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:39:23
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:39:16.216046 2026] [security2:error] [pid 7348:tid 7373] [client 104.23.170.6:12068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gafm.org"] [uri "/.env.local"] [unique_id "arxoRA-EL3QjDEJk7Tlb_AAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:55:06
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:54:59.254009 2026] [security2:error] [pid 7148:tid 7188] [client 104.23.170.6:13676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arthansl.com"] [uri "/.svn/entries"] [unique_id "arxd4_KJbtdfFL3JAUAT9gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-30 00:01:23
(16 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Trueforce Threat Report
2026-09-29 22:53:58
(17 hours ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 22:23:09
(18 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ฉ๐ช
raph
2026-09-29 21:59:40
(18 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:38:17
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:38:13.145220 2026] [security2:error] [pid 2530:tid 2530] [client 104.23.170.6:14247] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.recetabook.com"] [uri "/.env.production"] [unique_id "arwvxfT64pRcFhC1K_zsjQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 20:06:36
(20 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack