๐บ๐ธ
TPI-Abuse
2026-10-07 02:51:56
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:51:50.452468 2026] [security2:error] [pid 26098:tid 26098] [client 104.23.170.96:10223] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||evolutionmedical.help|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "evolutionmedical.help"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asWzxuzYwqWNnTCsyPBWeAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 02:33:26
(8 hours ago)
[07/Oct/2026:05:33:25 +0300] -- 104.23.170.96 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[07/Oct/2026:05:33:25 +0300] -- 104.23.170.96 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.staging HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:26:38
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:26:33.669648 2026] [security2:error] [pid 4751:tid 4758] [client 104.23.170.96:13808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertagmetairie.com"] [uri "/.env.backup"] [unique_id "asWt2QwkDBcYvGA9WJr_oAAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 01:48:30
(9 hours ago)
(mod_security) mod_security (id:949110) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:48:12.464664 2026] [security2:error] [pid 17652:tid 17652] [client 104.23.170.96:10321] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/.env.old"] [unique_id "asWk3GWs25e-8vAcc3DGNQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:51:29
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:51:19.494431 2026] [security2:error] [pid 21303:tid 21303] [client 104.23.170.96:12213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pjbruner.com"] [uri "/.env.staging"] [unique_id "asUK53auKmeoEH5UbUUCOQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:29:58
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:29:52.728588 2026] [security2:error] [pid 3041:tid 3062] [client 104.23.170.96:12227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taxelon.com"] [uri "/.env.production"] [unique_id "asT30NI7o_NDM6XivY4QSgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 23:51:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 19:51:08.655544 2026] [security2:error] [pid 4056:tid 4056] [client 104.23.170.96:12646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brbcash.com"] [uri "/.git/HEAD"] [unique_id "asQ37A4z38qQXW5BP-lJjQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 22:52:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:52:03.218764 2026] [security2:error] [pid 4367:tid 4367] [client 104.23.170.96:13441] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathewyoung.com"] [uri "/.env.dev"] [unique_id "asQqE6RkQ3NqxeVNqg9mmAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-03 04:10:20
(4 days ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
Inartis
2026-10-01 14:40:05
(5 days ago)
104.23.170.96 - - [01/Oct/2026:16:39:55 +0200] "GET /.env.production HTTP/1.1" 403 7823 "-" "Mozilla ...
show more
104.23.170.96 - - [01/Oct/2026:16:39:55 +0200] "GET /.env.production HTTP/1.1" 403 7823 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
104.23.170.96 - - [01/Oct/2026:16:40:02 +0200] "GET /.env HTTP/1.1" 403 7606 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
104.23.170.96 - - [01/Oct/2026:16:40:02 +0200] "GET /.env.staging HTTP/1.1" 403 7606 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 09:54:48
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:54:39.442392 2026] [security2:error] [pid 9445:tid 9445] [client 104.23.170.96:13780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lisalehmann.com"] [uri "/.env.local"] [unique_id "ar4t30ZUoUpTySEKOXCdtAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 03:05:25
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:05:16.622081 2026] [security2:error] [pid 32442:tid 32442] [client 104.23.170.96:9727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynthiabaxter.com"] [uri "/.env"] [unique_id "ar3N7LfBk6G7vEt9AsbpqQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:33:05
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:33:02.271172 2026] [security2:error] [pid 728:tid 728] [client 104.23.170.96:12894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acquivest.net"] [uri "/.env.staging"] [unique_id "ar2qPlR3JO3bZ-kFqGizbAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:08:23
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.170.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:08:17.349460 2026] [security2:error] [pid 32114:tid 32114] [client 104.23.170.96:12501] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.astariamusic.com"] [uri "/wp-config.php"] [unique_id "ar0z8anM-v-PoEDujdITkwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-30 14:36:16
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack