๐บ๐ธ
TPI-Abuse
2026-10-06 14:42:55
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:42:51.208084 2026] [security2:error] [pid 985:tid 985] [client 141.101.76.20:14022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bikiniwatersports.com"] [uri "/.svn/entries"] [unique_id "asUI63REx4yERT5JzOoZtgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:45:31
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:45:25.509550 2026] [security2:error] [pid 9907:tid 9925] [client 141.101.76.20:11453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vancekelly.com"] [uri "/wp-config.php.save"] [unique_id "asT7db9bwjlpPAsJorU_mwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:19:12
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:19:07.504317 2026] [security2:error] [pid 3041:tid 3048] [client 141.101.76.20:13848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taxelon.com"] [uri "/.git/HEAD"] [unique_id "asT1S9I7o_NDM6XivY4J1wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-06 11:26:37
(3 hours ago)
[TueOct0613:26:33.3192672026][security2:error][pid2218214:tid2218235][client141.101.76.20:0]ModSecur ...
show more
[TueOct0613:26:33.3192672026][security2:error][pid2218214:tid2218235][client141.101.76.20:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"hostingsvizzera.ch\"][uri\"/wp-config.php.old\"][unique_id\"asTa6c3hU_136aFIQppcYQAAAJM\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-10-06 11:07:00
(3 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-config\.php (Match: /wp-config.php)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 05:58:25
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 01:58:15.061477 2026] [security2:error] [pid 528:tid 528] [client 141.101.76.20:13291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "terryhildebrandprints.com"] [uri "/.env.backup"] [unique_id "asSN99Q34UjNTYr_0Wz2mwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 03:46:08
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 23:46:03.392231 2026] [security2:error] [pid 19377:tid 19377] [client 141.101.76.20:11946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horsesaw.com"] [uri "/.env.save"] [unique_id "asRu-ynxuDKHocji3Kve2gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 02:49:26
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 22:49:23.294015 2026] [security2:error] [pid 10227:tid 10227] [client 141.101.76.20:12820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "landjudging.com"] [uri "/.env.production"] [unique_id "asRhs4LkTKdzZXUWuU-pRgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 01:44:47
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 21:44:38.907583 2026] [security2:error] [pid 17642:tid 17642] [client 141.101.76.20:10945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "owengmail.com"] [uri "/.env.local"] [unique_id "asRShqzc8Gl4-8CKQnJ2EQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-06 00:33:47
(14 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-05 23:16:48
(15 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ฉ๐ช
MarkGGN
2026-10-05 03:00:10
(1 day ago)
Web attack. 141.101.76.20 - - [05/Oct/2026:05:00:00 +0200] "GET /.env.staging HTTP/2.0" 200 0 "-" "M ...
show more
Web attack. 141.101.76.20 - - [05/Oct/2026:05:00:00 +0200] "GET /.env.staging HTTP/2.0" 200 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
141.101.76.20 - - [05/Oct/2026:05:00:08 +0200] "GET /.env.dev HTTP/2.0" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
show less
Web App Attack
๐ฆ๐บ
dyln
2026-10-04 19:55:59
(1 day ago)
Dyls honeypot brute-force: proto8 (3 total hits)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-04 15:06:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 11:06:09.723374 2026] [security2:error] [pid 25958:tid 25958] [client 141.101.76.20:11505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "handankoc.net"] [uri "/.env.backup"] [unique_id "asJrYTInhNW8drhvtCCSbgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 02:19:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 22:19:46.155688 2026] [security2:error] [pid 606:tid 606] [client 141.101.76.20:11083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saramics.net"] [uri "/.env.backup"] [unique_id "asG3wuMTn60uwCJXQTFdWQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack