🇺🇸
SX Communications
2026-09-01 04:50:43
(5 days ago)
Blocked abusive HTTP application-layer DoS / botnet traffic from 23.236.230.6: traffic from this add ...
show more
Blocked abusive HTTP application-layer DoS / botnet traffic from 23.236.230.6: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
🇺🇸
TPI-Abuse
2026-04-12 18:22:25
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 12 14:22:20.183774 2026] [security2:error] [pid 3206923:tid 3206938] [client 23.236.230.6:50557] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madring.click"] [uri "/.env.backup"] [unique_id "advi3KwDO9ZlXppIYmzm-wAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-09 04:57:51
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 00:57:45.186403 2026] [security2:error] [pid 107663:tid 107663] [client 23.236.230.6:60994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prostar.industries"] [uri "/.env"] [unique_id "adcxyZoO95ARWqn3Qaw6CAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-09 02:43:41
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 22:43:37.343495 2026] [security2:error] [pid 2190173:tid 2190180] [client 23.236.230.6:34099] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "promoralchoice.org"] [uri "/.git/config"] [unique_id "adcSWbDhYdNF5lVMrulcfQAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-08 00:25:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 20:25:45.323644 2026] [security2:error] [pid 2140959:tid 2140959] [client 23.236.230.6:55383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portorock.hiphop"] [uri "/.env.test"] [unique_id "adWgiTJCXqXNQSOGRlHXQgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-07 10:10:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 06:10:14.859555 2026] [security2:error] [pid 1000067:tid 1000177] [client 23.236.230.6:35938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ayubhamdardfoundation.org"] [uri "/.env.test"] [unique_id "adTYBkOMnFhX_NMPE_XKzAAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-06 16:23:44
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 12:23:36.734696 2026] [security2:error] [pid 150768:tid 150768] [client 23.236.230.6:60525] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atsgroup.llc"] [uri "/wp-config.php"] [unique_id "adPeCOgUdvm1ytyFBwg04AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-06 13:51:00
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 09:50:54.948897 2026] [security2:error] [pid 302866:tid 302866] [client 23.236.230.6:36302] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||athletefirst.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "athletefirst.org"] [uri "/database.sql"] [unique_id "adO6Pr08Xux7uUK6jYmYZgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-04-06 01:52:17
(5 months ago)
[MonApr0603:52:13.2915252026][security2:error][pid2910673:tid2910716][client23.236.230.6:0]ModSecuri ...
show more
[MonApr0603:52:13.2915252026][security2:error][pid2910673:tid2910716][client23.236.230.6:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\\\\\\\\.sql\(\?:\$\|\\\\\\\\.\(\?:zip\|\(\?:t\|r\)ar\\\\\\\\.\?g\?z\?\|t\?\(\?:g\|b\)z\|old\|ba\(\?:k\|c\)u\?p\?\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1183\"][id\"350590\"][rev\"3\"][msg\"Atomicorp.comWAFRules:AttackBlocked-Dataleakage-attempttoaccessrawSQLfiles\(disablethisruleifyourequireaccesstofilesthatendwith.sql\)\"][severity\"CRITICAL\"][hostname\"artisteer-italia.org\"][uri\"/backup.sql.gz\"][unique_id\"adMRze8WrsQPJvk7WTRFowAAAEQ\"]
show less
Port Scan
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-04-05 21:59:03
(5 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-04-04.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-04-05 02:27:21
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 22:27:17.305109 2026] [security2:error] [pid 15880:tid 15880] [client 23.236.230.6:52123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anxo.org"] [uri "/.env.test"] [unique_id "adHIhXPypp-dq06fqxx-0QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-03 21:15:34
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 23.236.230.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 17:15:27.764312 2026] [security2:error] [pid 24447:tid 24498] [client 23.236.230.6:53725] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||careofsouls.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "careofsouls.org"] [uri "/database.sql"] [unique_id "adAt7-CKzb3dsSkFl5zkcAAAAZM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
IROK
2026-03-30 02:01:18
(5 months ago)
Malware/WebShell Scan blocked by ModSecurity
...
Hacking
Anonymous
2026-03-28 17:20:05
(5 months ago)
suspicious request in access.log
Web App Attack
🇺🇸
mw
2026-03-28 04:05:26
(5 months ago)
GET /.env.staging HTTP/1.1
Web App Attack