πΊπΈ
TPI-Abuse
2026-07-29 16:31:28
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 12:31:16.699699 2026] [security2:error] [pid 3716513:tid 3716513] [client 104.23.245.146:14144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desimon.com"] [uri "/.env.save"] [unique_id "amoq1Dy0gL5y-mEEHSox4gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-07-29 14:33:15
(12 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 3 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 21:21:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 17:21:04.541842 2026] [security2:error] [pid 1275066:tid 1275189] [client 104.23.245.146:10990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jd-web-designs.com"] [uri "/.git/HEAD"] [unique_id "amkdQHsIZtvyfz5qvnYo1wAAANg"], referer: https://www.google.com/search?q=jd-web-designs.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-07-22 08:10:27
(1 week ago)
Persistent port scanning or vulnerability scanning
Port Scan
πΊπΈ
TPI-Abuse
2026-06-19 00:26:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 20:26:49.417609 2026] [security2:error] [pid 20638:tid 20638] [client 104.23.245.146:13829] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portfolio-realestate.com"] [uri "/.env.local"] [unique_id "ajSMyQ8O_Aa9K3vBSay_ZQAAAAU"], referer: https://www.google.com/search?q=portfolio-realestate.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-17 03:37:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 23:37:15.766103 2026] [security2:error] [pid 9837:tid 9837] [client 104.23.245.146:9402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.janicestewart.net"] [uri "/.env"] [unique_id "ajIWax0B9ms3AcULDoRzQQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-06-17 03:07:18
(1 month ago)
Abuse Detected (1)
Brute-Force
Web App Attack
π³π±
homeshowdomain.nl
2026-06-16 22:00:43
(1 month ago)
Auto-ban: >3000 req/min op 2026-06-16
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-06-14 10:12:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.245.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.245.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:12:09.054990 2026] [security2:error] [pid 1197:tid 1197] [client 104.23.245.146:13448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tdj.franchiseconsultants.org"] [uri "/.env.development.local"] [unique_id "ai5-eTq40Wdh1houk-ZFvQAAAB4"], referer: https://www.google.com/search?q=tdj.franchiseconsultants.org
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
COMPLEX
2026-05-29 01:11:42
(2 months ago)
Unsolicited TCP traffic | Action: DROP | Port 443
Phishing
πΊπΈ
mawan
2026-04-25 02:09:40
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
myagent.site
2026-04-07 15:43:51
(3 months ago)
Blocking for trying to access an exploit file: /home/.env
Hacking
πΊπΈ
Void Vendor
2026-03-06 03:08:56
(4 months ago)
VoidTrap [15,21]: [offense #1 β 30 minutes] Redirect loop trap: /wp-admin/setup-config.p | ip: 104.2 ...
show more
VoidTrap [15,21]: [offense #1 β 30 minutes] Redirect loop trap: /wp-admin/setup-config.p | ip: 104.23.245.146 | loc: Atlanta, Georgia, US, AS13335 Cloudflare, Inc. | path: /wp-admin/setup-config.php | ua: http://voidvendor.com/wp-admin/setup-config.php
show less
Hacking
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-01-16 22:41:24
(6 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
πΊπΈ
mawan
2025-12-15 23:22:04
(7 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack