๐บ๐ธ
TPI-Abuse
2026-10-01 16:10:40
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:10:35.956093 2026] [security2:error] [pid 28464:tid 28522] [client 104.23.187.172:10649] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||seanmeriwether.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "seanmeriwether.com"] [uri "/index.php.bak"] [unique_id "ar6F-3j1P4yjetc8l4VELgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:49:51
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:49:48.500683 2026] [security2:error] [pid 685:tid 685] [client 104.23.187.172:14046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1214productions.com"] [uri "/wp-config.php"] [unique_id "ar5W7BYc-CPwD8Ym5roZEwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:48:27
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:48:19.955630 2026] [security2:error] [pid 3674:tid 3674] [client 104.23.187.172:10578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stardancertantra.com"] [uri "/.git/config"] [unique_id "ar46c_Mmy7mzhINI1NlaqwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 04:36:28
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:36:24.897996 2026] [security2:error] [pid 18882:tid 18882] [client 104.23.187.172:14003] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.goodacoustic.com"] [uri "/.htaccess"] [unique_id "ar3jSEpxn40oIUWtUEfd6QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:34:04
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:33:57.957596 2026] [security2:error] [pid 961:tid 961] [client 104.23.187.172:11270] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||acquivest.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "acquivest.net"] [uri "/index.php.bak"] [unique_id "ar2qdVQGQqSn2aXb8oweggAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:24:45
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:24:38.497863 2026] [security2:error] [pid 3372:tid 3372] [client 104.23.187.172:10856] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||geckoturner.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "geckoturner.com"] [uri "/index.php.bak"] [unique_id "ar03xrdORW73HnAA5sN2MwAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-25 15:25:34
(6 days ago)
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-08-21 06:35:11
(1 month ago)
104.23.187.172 - - [21/Aug/2026:09:35:10 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.p ...
show more
104.23.187.172 - - [21/Aug/2026:09:35:10 +0300] "GET /wp-content/plugins/hellopress/wp_filemanager.php HTTP/2.0" 404 134 "-" "-"
...
show less
Hacking
Web App Attack
๐ง๐ช
madeit
2026-08-06 14:17:15
(1 month ago)
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-07-23 11:32:46
(2 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฒ๐ฝ
octageeks.com
2026-07-09 04:07:52
(2 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 13:25:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.187.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 09:25:32.145504 2026] [security2:error] [pid 23747:tid 23747] [client 104.23.187.172:11046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jazziientertainment.com"] [uri "/.env.local"] [unique_id "ajVDTCSrYCHfYY9f0LXccgAAAAo"], referer: https://www.google.com/search?q=jazziientertainment.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-16 00:15:37
(3 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-06-13 14:22:50
(3 months ago)
104.23.187.172 - - [13/Jun/2026:17:22:49 +0300] "GET /.env.production HTTP/2.0" 404 134 "-" "Mozilla ...
show more
104.23.187.172 - - [13/Jun/2026:17:22:49 +0300] "GET /.env.production HTTP/2.0" 404 134 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:149.0) Gecko/20100101 Firefox/149.0"
...
show less
Hacking
Web App Attack
๐บ๐ธ
wimaxnz
2026-06-13 06:22:53
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan