๐บ๐ธ
terraforge.fun
2026-06-18 15:33:10
(4 days ago)
Blocked by on us-1-terraforge [8443/tcp] | SPT: 10613 | TTL: 56 | LEN: 60 | TOS: 0x00 โข Reported by: ...
show more
Blocked by on us-1-terraforge [8443/tcp] | SPT: 10613 | TTL: 56 | LEN: 60 | TOS: 0x00 โข Reported by: terraforge.fun
show less
Port Scan
๐บ๐ธ
mnsf
2026-06-17 00:07:53
(6 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ฌ๐ง
Axel
2026-06-01 22:33:21
(3 weeks ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /api/.env Ser ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /api/.env Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ฌ๐ง
Axel
2026-06-01 22:10:02
(3 weeks ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env Server: ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ฌ๐ง
Axel
2026-05-22 00:09:32
(1 month ago)
Blocked by ModSecurity. Rule ID: 225170 Message: COMODO WAF: Sensitive Information Disclosure Vulner ...
show more
Blocked by ModSecurity. Rule ID: 225170 Message: COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||redcasiepac.com|F|2 Phase: 2 Severity: CRITICAL URI: /wp-json/wp/v2/users Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ฆ
URAN Publishing Service
2026-04-23 20:25:43
(1 month ago)
104.23.253.76 - - [23/Apr/2026:23:25:42 +0300] "GET /wp-content/plugins/ HTTP/1.1" 404 762 "-" "Mozl ...
show more
104.23.253.76 - - [23/Apr/2026:23:25:42 +0300] "GET /wp-content/plugins/ HTTP/1.1" 404 762 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
104.23.253.76 - - [23/Apr/2026:23:25:42 +0300] "GET /wp-admin/ HTTP/1.1" 404 761 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-15 16:51:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 12:51:43.026598 2026] [security2:error] [pid 3718950:tid 3718950] [client 104.23.253.76:12438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rockylranch.com"] [uri "/.env.backup"] [unique_id "ad_CHzsY056h5kf7baO-iAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 12:51:07
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 08:50:59.292097 2026] [security2:error] [pid 2263:tid 2263] [client 104.23.253.76:9975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.carjinn.net"] [uri "/.env_secret"] [unique_id "adEJM-OOua8g2QdBgUW1ZgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-27 09:05:24
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-03-24 19:16:39
(2 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-stl2-14)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 06:03:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 02:03:41.320155 2026] [security2:error] [pid 25995:tid 25995] [client 104.23.253.76:12477] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americanacademyofteachersofsinging.org"] [uri "/.env.local"] [unique_id "ab40vb4UkNeUhqUuxmNM5wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:58:43
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:58:38.452567 2026] [security2:error] [pid 24639:tid 24639] [client 104.23.253.76:9706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.glaswood.com"] [uri "/.envrc"] [unique_id "ab37TiwDnheTSP8JRc542QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-21 01:08:38
(3 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:38:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:38:48.876373 2026] [security2:error] [pid 24937:tid 24937] [client 104.23.253.76:13099] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aangfl.com"] [uri "/.env.prod"] [unique_id "abzreJXqjm4eIT6d_cDubgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:17:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:17:53.700184 2026] [security2:error] [pid 14922:tid 14922] [client 104.23.253.76:14208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jetpower.com"] [uri "/.env.old"] [unique_id "abzYgU4ribnAeFeJAPRQTQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack