π§πͺ
madeit
2026-10-05 01:37:11
(3 days ago)
Web App Attack
π§πͺ
madeit
2026-08-20 06:38:01
(1 month ago)
Web App Attack
π§πͺ
madeit
2026-08-06 07:58:10
(2 months ago)
Web App Attack
π«π·
Baking333
2026-05-23 09:13:06
(4 months ago)
[redacted] 104.23.253.87 - - [23/May/2026:10:13:03 +0100] "GET /fr/.[redacted]/ HTTP/2.0" 404 24985 ...
show more
[redacted] 104.23.253.87 - - [23/May/2026:10:13:03 +0100] "GET /fr/.[redacted]/ HTTP/2.0" 404 24985 "https://[redacted]/.[redacted]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:149.0) Gecko/20100101 Firefox/149.0" [redacted] 104.23.253.87 - - [23/May/2026:10:13:04 +0100] "GET /fr/.[redacted]/ HTTP/2.0" 404 24827 "https://[redacted]/.[redacted]" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_7_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Safari/605.1.15"
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-05 14:07:19
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 10:07:15.563429 2026] [security2:error] [pid 12022:tid 12022] [client 104.23.253.87:10186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.seacorre.de"] [uri "/.env_config"] [unique_id "adJsk8RMLiy4OthyHQ-lmwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 03:17:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 23:17:07.661626 2026] [security2:error] [pid 23950:tid 23950] [client 104.23.253.87:9367] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.whaletailpuckerbutt.com"] [uri "/.env.dist"] [unique_id "adCCs8-p7ycjh9B7yRkrrgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mawan
2026-03-30 22:57:07
(6 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
LotPhantom
2026-03-30 19:19:53
(6 months ago)
2026/03/30 19:19:52 [error] 109153#109153: *62804 access forbidden by rule, client: 104.23.253.87, s ...
show more
2026/03/30 19:19:52 [error] 109153#109153: *62804 access forbidden by rule, client: 104.23.253.87, server: api.bridginggaps.tech, request: "GET /var/www/html/.env HTTP/2.0", host: "api.bridginggaps.tech"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-21 03:58:16
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 23:58:08.696841 2026] [security2:error] [pid 28411:tid 28411] [client 104.23.253.87:10714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.herston.us.herston.net"] [uri "/.env.php"] [unique_id "ab4XUHsy6gZPJwF-u_7AbgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-21 02:38:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:38:17.260252 2026] [security2:error] [pid 12701:tid 12701] [client 104.23.253.87:11217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.medusakenya.com"] [uri "/.env.development.local"] [unique_id "ab4EmWQtZs3q674ZRGTzbwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 09:01:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 05:01:22.574978 2026] [security2:error] [pid 8013:tid 8013] [client 104.23.253.87:10770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10bestcountryclubs.directoryofbikes.com"] [uri "/private/.env"] [unique_id "ab0M4ok3HtXxQKeheOiGJQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 08:32:47
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:32:35.601720 2026] [security2:error] [pid 23053:tid 23053] [client 104.23.253.87:10229] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stern2.darkhorseyachting.com"] [uri "/.env_backup"] [unique_id "ab0GI37YaBqc21wbuvKOXAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 07:19:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:18:52.852493 2026] [security2:error] [pid 2821:tid 2821] [client 104.23.253.87:13778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.grabnerconsulting.com"] [uri "/docker/.env.local"] [unique_id "abz03CmSTOI6gQaKn0Ll9QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 06:55:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:55:19.101002 2026] [security2:error] [pid 29808:tid 29808] [client 104.23.253.87:12218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.weismanovens.com"] [uri "/root/.env"] [unique_id "abzvV68CrGOkaI_mwB1L3QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 06:27:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:27:14.863011 2026] [security2:error] [pid 31674:tid 31674] [client 104.23.253.87:10803] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.penjoki.us"] [uri "/.git/refs/heads/main"] [unique_id "abzowh__0mWBZS3eidCEaAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack