π¨π
4server
2026-05-06 21:33:59
(4 weeks ago)
[WedMay0623:33:50.6826652026][security2:error][pid1341705:tid1341986][client104.23.239.81:0]ModSecur ...
show more
[WedMay0623:33:50.6826652026][security2:error][pid1341705:tid1341986][client104.23.239.81:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"server-privato.ch\"][uri\"/.env.vercel\"][unique_id\"afuzvhrobVt0wWbOchQfTAAAAQo\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-05 00:11:29
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 20:11:24.493466 2026] [security2:error] [pid 16771:tid 16780] [client 104.23.239.81:12152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "triestemagica.org"] [uri "/.git/config"] [unique_id "afk1rPCDyO5b7aILF3McJwAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-04 19:45:35
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 15:45:31.490635 2026] [security2:error] [pid 9003:tid 9078] [client 104.23.239.81:10236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boracayglobal.org"] [uri "/.git/config"] [unique_id "afj3Wy65TSsV4Xu4HZxgoQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
trentwiles.com
2026-05-04 15:23:45
(4 weeks ago)
Unauthorized connection attempt detected from IP address 104.23.239.81 to port 443 [SYD]
Port Scan
πΊπΈ
TPI-Abuse
2026-05-04 13:39:55
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 09:39:51.087705 2026] [security2:error] [pid 6780:tid 6780] [client 104.23.239.81:10100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lilachost.net"] [uri "/.git/config"] [unique_id "afihp5OOK40GSl8sbyVEMwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-03 08:09:59
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 04:09:53.763857 2026] [security2:error] [pid 16678:tid 16678] [client 104.23.239.81:9507] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "astglobaltech.com"] [uri "/.git/config"] [unique_id "afcC0bM1iA4DCw7GQEwp8AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-30 18:07:23
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 14:07:18.584055 2026] [security2:error] [pid 10633:tid 10633] [client 104.23.239.81:9515] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.realitytourist.com"] [uri "/.git/config"] [unique_id "afOaVhRocdpxkIX6AufvwgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-30 11:59:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 07:59:14.497840 2026] [security2:error] [pid 27876:tid 27882] [client 104.23.239.81:9881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.internationalacademyofprojectmanagement.com"] [uri "/.git/config"] [unique_id "afNEEgykR_CGDPcHFYl2UQAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-30 08:23:28
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 04:23:24.132167 2026] [security2:error] [pid 17246:tid 17246] [client 104.23.239.81:9748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.garyrankin.com"] [uri "/.git/config"] [unique_id "afMRfFjF5AvVizFnMGB0LgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-30 07:23:36
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 03:23:30.158698 2026] [security2:error] [pid 29696:tid 29696] [client 104.23.239.81:10059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.klingandi.com"] [uri "/.git/config"] [unique_id "afMDcouhzUuhzh0zah3DawAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
librebit
2026-04-24 18:06:12
(1 month ago)
Brute force
Brute-Force
π¦πΊ
trentwiles.com
2026-04-23 14:00:41
(1 month ago)
Unauthorized connection attempt detected from IP address 104.23.239.81 to port 443 [SYD]
Port Scan
π«π·
SpaceHost-Server
2026-04-22 22:25:48
(1 month ago)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-22 20:02:18
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.239.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 16:02:13.909267 2026] [security2:error] [pid 21346:tid 21346] [client 104.23.239.81:10114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tonyv.org"] [uri "/.env.production.local"] [unique_id "aekpRaveB3zeI69dkzwx0QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
macrob
2026-04-22 07:02:47
(1 month ago)
2026/04/22 07:02:22 [error] 2168223#2168223: *169423454 access forbidden by rule, client: 104.23.239 ...
show more
2026/04/22 07:02:22 [error] 2168223#2168223: *169423454 access forbidden by rule, client: 104.23.239.81, server: binixo.com.ua, request: "GET /config/.env HTTP/2.0", host: "binixo.com.ua"
2026/04/22 07:02:23 [error] 2168223#2168223: *169423454 access forbidden by rule, client: 104.23.239.81, server: binixo.com.ua, request: "GET /backend/.env HTTP/2.0", host: "binixo.com.ua"
2026/04/22 07:02:23 [error] 2168223#2168223: *169423454 access forbidden by rule, client: 104.23.239.81, server: binixo.com.ua, request: "GET /src/.env HTTP/2.0", host: "binixo.com.ua"
...
show less
Web App Attack