๐บ๐ธ
TPI-Abuse
2026-10-06 20:45:46
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:45:36.997823 2026] [security2:error] [pid 11053:tid 11053] [client 104.23.170.84:13211] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||clowaterart.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clowaterart.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asVd8GVRV5rVNAZfeFtHEgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:49:41
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:49:33.983826 2026] [security2:error] [pid 31186:tid 31186] [client 104.23.170.84:12329] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||juhoanttila.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "juhoanttila.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asUYjQ5NpatqU9JgtZS5HAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:12:48
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:12:39.826462 2026] [security2:error] [pid 12624:tid 12624] [client 104.23.170.84:13352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "essentialee.com"] [uri "/.env"] [unique_id "asUP56WVu1cnDmHeauG_bAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:46:05
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:45:57.569846 2026] [security2:error] [pid 21744:tid 21744] [client 104.23.170.84:10215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wedemandavote.com"] [uri "/.env.old"] [unique_id "asUJpWcFyauKrinKEo_L_AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-10-06 13:02:27
(11 hours ago)
bad bot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 01:42:29
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 21:42:23.653728 2026] [security2:error] [pid 22649:tid 22649] [client 104.23.170.84:11959] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtrl.com"] [uri "/wp-config.php.bak"] [unique_id "asRR_0NZCa60g6onpVZgwAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 22:56:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:55:58.741984 2026] [security2:error] [pid 26589:tid 26589] [client 104.23.170.84:13567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horsesaw.com"] [uri "/.env.bak"] [unique_id "asQq_u6zxb2lawqBGTY0iwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 20:37:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 16:37:23.681064 2026] [security2:error] [pid 13464:tid 13464] [client 104.23.170.84:11854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathewyoung.com"] [uri "/.git/HEAD"] [unique_id "asQKg7bG_uhPCfXIfTN_7gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 09:29:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 05:29:11.501567 2026] [security2:error] [pid 27179:tid 27179] [client 104.23.170.84:13570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "steveleeds.com"] [uri "/.env.save"] [unique_id "asNt5wsYRdfNXZH08mNBfQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.mammazone.it
2026-10-02 05:07:50
(4 days ago)
[Fri Oct 02 07:07:48.669587 2026] [access_compat:error] [pid 2730536] [client 104.23.170.84:14145] A ...
show more
[Fri Oct 02 07:07:48.669587 2026] [access_compat:error] [pid 2730536] [client 104.23.170.84:14145] AH01797: client denied by server configuration: /var/www/underdomotic.fabiodirauso.it/.config
[Fri Oct 02 07:07:48.709243 2026] [proxy_fcgi:error] [pid 2730536] [client 104.23.170.84:14145] AH01071: Got error 'Primary script unknown'
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 11:35:00
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:34:54.871988 2026] [security2:error] [pid 9108:tid 9108] [client 104.23.170.84:9921] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asiabeef.network"] [uri "/.git/config"] [unique_id "ar5FXnrxcUtPLmo9rwgBlgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-01 04:48:22
(5 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:36:07
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:36:01.594316 2026] [security2:error] [pid 2703:tid 2703] [client 104.23.170.84:12318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brexitop.com"] [uri "/.htaccess"] [unique_id "ar0CMfD71IhTPkwA5HdeCgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-30 06:24:46
(6 days ago)
[30/Sep/2026:09:24:45 +0300] -- 104.23.170.84 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[30/Sep/2026:09:24:45 +0300] -- 104.23.170.84 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
bohl-aiG5aef
2026-09-30 00:29:28
(6 days ago)
Suricata Alert [SID:2009955] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerab ...
show more
Suricata Alert [SID:2009955] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Web App Attack