๐บ๐ธ
TPI-Abuse
2026-10-08 18:28:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:28:49.594761 2026] [security2:error] [pid 16874:tid 16874] [client 104.23.170.89:14130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "interforce.com"] [uri "/.svn/entries"] [unique_id "asfg4bLzBP3ZdOdU1ymswwAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-10-08 17:29:32
(4 hours ago)
104.23.170.89 - - [08/Oct/2026:22:59:31 +0530] "GET /.env.staging HTTP/1.1" 301 162 "-" "Mozilla/5.0 ...
show more
104.23.170.89 - - [08/Oct/2026:22:59:31 +0530] "GET /.env.staging HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 14:04:20
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:04:09.285113 2026] [security2:error] [pid 21964:tid 21964] [client 104.23.170.89:9218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sunstrongmetal.com"] [uri "/.env.local"] [unique_id "asei2b09Jad9XiVcToJIPQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
VXG-NET
2026-10-08 11:51:28
(9 hours ago)
port=80, indicator_type=info-leak
Hacking
๐บ๐ธ
conrad10781
2026-10-08 10:42:34
(10 hours ago)
nginx-dot-env
Web App Attack
๐ช๐ธ
bohl-aiG5aef
2026-10-08 07:38:09
(14 hours ago)
Suricata Alert [SID:2009955] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerab ...
show more
Suricata Alert [SID:2009955] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:09:02
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:08:55.959796 2026] [security2:error] [pid 19608:tid 19608] [client 104.23.170.89:13625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bakerimaging.com"] [uri "/.env.production"] [unique_id "asdBh9On3vF9u-FMDjVClgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 07:02:17
(14 hours ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 104.23.170.89 - - [08/Oct/2026:09:02:08 +0200] "GET /.env.old HTTP/1.1" 301 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
David Koswari
2026-10-08 06:39:00
(14 hours ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
Anonymous
2026-10-08 05:48:42
(15 hours ago)
Sensitive Configuration File Disclosure.
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 03:40:30
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:40:25.328300 2026] [security2:error] [pid 7689:tid 7689] [client 104.23.170.89:12462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jdubindustries.com"] [uri "/.git/HEAD"] [unique_id "ascQqSB0j3uS-m5TgorKfgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-08 01:57:50
(19 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:37:23
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:37:03.925463 2026] [security2:error] [pid 8510:tid 8510] [client 104.23.170.89:9273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.takemehomedogrescue.org"] [uri "/.env"] [unique_id "asbzv2_tKyyqR70DRSTk9QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 00:41:06
(20 hours ago)
104.23.170.89 - - [08/Oct/2026:02:41:04 +0200] "GET /. HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows N ...
show more
104.23.170.89 - - [08/Oct/2026:02:41:04 +0200] "GET /. HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:24:31
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:24:27.518618 2026] [security2:error] [pid 8558:tid 8558] [client 104.23.170.89:13168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cruisingforsex.com"] [uri "/.env.save"] [unique_id "asbUq1kYlNT9sa5hymJTIAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack