๐ฏ๐ต
S.O.B.A. Dev.
2026-09-27 15:37:24
(2 days ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ง๐ช
madeit
2026-09-23 22:01:25
(5 days ago)
Web App Attack
๐ง๐ช
madeit
2026-09-08 10:28:15
(3 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-10 15:06:15
(1 month ago)
Web App Attack
๐บ๐ธ
mnsf
2026-04-04 13:05:59
(5 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
COMPLEX
2026-03-31 01:31:05
(5 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐บ๐ธ
mnsf
2026-03-27 10:05:33
(6 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 15:12:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 11:11:56.280722 2026] [security2:error] [pid 15223:tid 15223] [client 104.23.209.149:12962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.histbase.com"] [uri "/public/.env"] [unique_id "acAGvAxqRgyEK_6zcVy_UwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-22 15:05:27
(6 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 14:38:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 10:38:01.378683 2026] [security2:error] [pid 10066:tid 10066] [client 104.23.209.149:10811] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kewlkarz.com"] [uri "/.env.php"] [unique_id "ab_-yRufYGvO9za_L1TLywAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-22 01:01:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 21:01:47.514315 2026] [security2:error] [pid 31049:tid 31049] [client 104.23.209.149:14242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.phalanxemail.net"] [uri "/www/.env"] [unique_id "ab8_e3Pq9ge4yw44XOSxpQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 12:13:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 08:13:08.018899 2026] [security2:error] [pid 1307:tid 1307] [client 104.23.209.149:10786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ifmamasang.com"] [uri "/server/.env"] [unique_id "ab6LVDAhtcpTh7J4nD2OngAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:29:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:28:51.362960 2026] [security2:error] [pid 29991:tid 29991] [client 104.23.209.149:11070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perlcreative.com"] [uri "/config/.env"] [unique_id "ab4egw0rQrzwD4-CNXskYgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:40:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:40:25.519829 2026] [security2:error] [pid 981:tid 981] [client 104.23.209.149:11133] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tijuana-bibles.com"] [uri "/.env.json"] [unique_id "ab4FGQmo5XuCG1kppBGNUQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:54:20
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:54:12.166579 2026] [security2:error] [pid 8819:tid 8819] [client 104.23.209.149:13484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "steamboatrowena.com"] [uri "/.env.test"] [unique_id "ab36RJF_cUkv0FE2OzPWngAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack