π»π³
cimee
2026-09-11 02:48:55
(23 hours ago)
This IP accessed the path /.env.bak, which is banned.
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 13:54:21
(1 week ago)
Aggressive web scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 03:20:59
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 23:20:53.235952 2026] [security2:error] [pid 5401:tid 5415] [client 104.23.209.87:12893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.fayleuzzi.com"] [uri "/.git/HEAD"] [unique_id "aoPPldBfkU2LpJodmuwQuwAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 00:08:52
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 20:08:46.275514 2026] [security2:error] [pid 16044:tid 16044] [client 104.23.209.87:10032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.giganticmediallc.com"] [uri "/.git/config"] [unique_id "aoOijuLY3xxIsTvR2ebYigAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-17 21:02:22
(3 weeks ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 12:11:49
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:11:44.974325 2026] [security2:error] [pid 25409:tid 25409] [client 104.23.209.87:10620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bernard.gonzalez.com"] [uri "/.git/HEAD"] [unique_id "aoL6gDWp-uuToXgHll3X1QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 06:13:35
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:13:27.803570 2026] [security2:error] [pid 30204:tid 30204] [client 104.23.209.87:9972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "susansimmons.net"] [uri "/.git/config"] [unique_id "aoKmhxct3TxFPC89Zm6dKAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
paulshipley.com.au
2026-08-17 05:31:20
(3 weeks ago)
[Mon Aug 17 15:31:19.294449 2026] [security2:error] [pid 74760] [client 104.23.209.87:12435] [client ...
show more
[Mon Aug 17 15:31:19.294449 2026] [security2:error] [pid 74760] [client 104.23.209.87:12435] [client 104.23.209.87] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "balcomberetreat.com.au"] [uri "/.git/config"] [unique_id "aoKcpxbDWP5a0Y0Yh_NgFgAAAAM"]
...
show less
Web App Attack
π³π±
homeshowdomain.nl
2026-08-12 21:59:27
(4 weeks ago)
Auto-ban: >3000 req/min op 2026-08-12
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-11 03:33:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 23:33:50.272374 2026] [security2:error] [pid 784658:tid 784658] [client 104.23.209.87:11482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.e-ntourage.com"] [uri "/.git/HEAD"] [unique_id "anqYHjv48DbThhiYSpafSwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-09 06:32:39
(1 month ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 11:08:13
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:05:29.187798 2026] [security2:error] [pid 31891:tid 31891] [client 104.23.209.87:12339] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||seychelles-boat-registration.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "seychelles-boat-registration.com"] [uri "/backup.sql"] [unique_id "agb9-dlwnwVUzModF_wDowAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-04-05 15:05:43
(5 months ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-22 16:52:24
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 12:52:19.702361 2026] [security2:error] [pid 9067:tid 9067] [client 104.23.209.87:11943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cottrel.com"] [uri "/.env_backup"] [unique_id "acAeQ1UFX6IkJzOI4H0rngAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-22 15:24:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 11:24:25.420158 2026] [security2:error] [pid 23983:tid 23983] [client 104.23.209.87:10711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.conservadordehualpen.cl"] [uri "/.env.staging"] [unique_id "acAJqWcLvOOrLVWOhm_hagAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack