๐บ๐ธ
TPI-Abuse
2026-10-11 15:35:41
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 11 11:35:35.268771 2026] [security2:error] [pid 3750:tid 3750] [client 141.101.76.173:10286] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||peterndudar.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "peterndudar.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asusx3X0ZXHsQX1lrrJsagAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 03:39:17
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 23:39:12.391987 2026] [security2:error] [pid 8982:tid 8982] [client 141.101.76.173:10494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "w-c-p-m.com"] [uri "/.env.save"] [unique_id "assE4KlfnqTDZkDD9XBTQQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-10 19:16:54
(21 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
anon333
2026-10-10 08:06:07
(1 day ago)
Invalid probes to web server T0406
Hacking
Exploited Host
๐ช๐ธ
Gem
2026-10-09 22:08:01
(1 day ago)
Unauthorized web scan.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:59:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:59:18.465968 2026] [security2:error] [pid 24532:tid 24532] [client 141.101.76.173:12236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.connectigramme.com"] [uri "/.env.dev"] [unique_id "aslVpnydkfcByMF19oUp9wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:40:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:39:57.322302 2026] [security2:error] [pid 15784:tid 15784] [client 141.101.76.173:14111] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sponsorzilla.com"] [uri "/.env"] [unique_id "aslRHQDB38kg0YW4wPEY1gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 16:59:05
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:58:58.932007 2026] [security2:error] [pid 19246:tid 19260] [client 141.101.76.173:12824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.theyogicat.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.theyogicat.com"] [uri "/index.php.bak"] [unique_id "asfL0nte3G9lk2oxvbihcAAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
VXG-NET
2026-10-08 16:31:39
(3 days ago)
port=80, indicator_type=info-leak
Hacking
๐ฉ๐ช
altenglaner
2026-10-08 14:21:05
(3 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 13:18:25
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:18:20.071541 2026] [security2:error] [pid 2140:tid 2153] [client 141.101.76.173:10404] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||malia97.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "malia97.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "aseYHAX-5RHV2x0uCWXG0wAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 12:18:35
(3 days ago)
[08/Oct/2026:15:18:35 +0300] -- 141.101.76.173 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[08/Oct/2026:15:18:35 +0300] -- 141.101.76.173 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /secrets.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 10:13:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 06:13:03.926189 2026] [security2:error] [pid 12593:tid 12593] [client 141.101.76.173:11339] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matchstic-branding.com"] [uri "/.env"] [unique_id "asdsr36DndnfYf0VvdG9OwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:46:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:46:50.099962 2026] [security2:error] [pid 2101:tid 2101] [client 141.101.76.173:11525] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accentcorporatemedia.com"] [uri "/wp-config.php"] [unique_id "ascgOnVmBrWLE58TFdzf1wAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:06:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:06:15.710751 2026] [security2:error] [pid 12052:tid 12052] [client 141.101.76.173:12256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fluff3.instagenii.com"] [uri "/.svn/entries"] [unique_id "ascIp1CJFa1YACnDcTGDggAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack