๐ฉ๐ช
IVski.com
2026-08-23 03:18:42
(2 days ago)
IVski WAF | Sensitive file probe - looking for exposed .env.bak
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 21:07:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 17:07:18.347541 2026] [security2:error] [pid 3754:tid 3754] [client 104.23.211.97:11537] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.supaskills.gregorii.com"] [uri "/.env.test"] [unique_id "aooPhiLbCoIEjVrxBfBqYAAAAAo"], referer: https://www.google.com/search?q=www.supaskills.gregorii.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-22 12:47:47
(3 days ago)
[SatAug2214:47:39.1950922026][security2:error][pid2469914:tid2470287][client104.23.211.97:0]ModSecur ...
show more
[SatAug2214:47:39.1950922026][security2:error][pid2469914:tid2470287][client104.23.211.97:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"465\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"rssolution.ch\"][uri\"/.env.test\"][unique_id\"aomaa6uOzN5zKjllLou7BgAAAQk\"]\,referer:https://www.google.com/search\?q=rssolution.ch
show less
Hacking
Web App Attack
Anonymous
2026-08-18 04:17:32
(1 week ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 03:00:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 23:00:38.768635 2026] [security2:error] [pid 5101:tid 5101] [client 104.23.211.97:10135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-hong-kong.com"] [uri "/.git/HEAD"] [unique_id "aoPK1t_xvLAPs5RQJVdyAgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 12:50:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:50:25.889156 2026] [security2:error] [pid 30694:tid 30914] [client 104.23.211.97:10928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killyourattitude.com"] [uri "/.git/config"] [unique_id "aoMDkcULDaCXKWrl15xJCQAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 12:13:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:13:18.174380 2026] [security2:error] [pid 27345:tid 27345] [client 104.23.211.97:13143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.climasyequipos.com"] [uri "/.git/config"] [unique_id "aoL63mo2PnyDrUyRawogsAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:16:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:15:56.452526 2026] [security2:error] [pid 305:tid 305] [client 104.23.211.97:9685] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.donaldcoleman.com"] [uri "/.git/config"] [unique_id "aoLRTO_qqlrWiSJnUr01vgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-17 04:56:02
(1 week ago)
[17/Aug/2026:07:56:02 +0300] -- 104.23.211.97 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[17/Aug/2026:07:56:02 +0300] -- 104.23.211.97 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 00:34:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 20:34:30.227577 2026] [security2:error] [pid 11139:tid 11226] [client 104.23.211.97:12285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.casademontemaior.com"] [uri "/.git/config"] [unique_id "aoJXFntlcMtAbgUWn8sNYQAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:34:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:33:53.844084 2026] [security2:error] [pid 23322:tid 23322] [client 104.23.211.97:13767] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thecollective.org"] [uri "/.git/HEAD"] [unique_id "aoF18bZ8UZ1m2SrO7eyubAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:08:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:08:14.641208 2026] [security2:error] [pid 24700:tid 24700] [client 104.23.211.97:9480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coralseasbeach.com"] [uri "/.git/HEAD"] [unique_id "aoFv7tUSADLP-kCM_1_iNAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-08-16 07:02:09
(1 week ago)
Accessed trap at '/.git/HEAD'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:57:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:57:49.556050 2026] [security2:error] [pid 773:tid 773] [client 104.23.211.97:12167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jiggajones.indie100.com"] [uri "/.git/HEAD"] [unique_id "aoFfbawU2jXkyZqYNT2-4gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:09:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.211.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:09:30.193044 2026] [security2:error] [pid 7974:tid 7974] [client 104.23.211.97:11613] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.brasscadillac.com"] [uri "/.git/config"] [unique_id "aoFGCj94tOd9hDRLxUl3cAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack