๐บ๐ธ
TPI-Abuse
2026-10-08 16:26:05
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:26:01.252811 2026] [security2:error] [pid 27805:tid 27805] [client 141.101.76.21:13258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tckgbookkeeping.biz"] [uri "/.env.dev"] [unique_id "asfEGeMB0pE3cHZhC28UJAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 12:18:33
(14 hours ago)
[08/Oct/2026:15:18:32 +0300] -- 141.101.76.21 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[08/Oct/2026:15:18:32 +0300] -- 141.101.76.21 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.docker/config.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:12:03
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:11:57.254854 2026] [security2:error] [pid 3840:tid 3856] [client 141.101.76.21:13096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.southtampaprinting.com"] [uri "/wp-config.php"] [unique_id "asc0LVyNHKJtVPszKReZrQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:08:51
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:08:42.436807 2026] [security2:error] [pid 21991:tid 21991] [client 141.101.76.21:11564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fatcaverecords.com"] [uri "/.env.production"] [unique_id "ascXSmzdfPM9332d7Ts-HgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ธ
Smel
2026-10-08 00:52:41
(1 day ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:01:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:01:34.255020 2026] [security2:error] [pid 6217:tid 6217] [client 141.101.76.21:12043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "almudenastrust.com"] [uri "/.env.production"] [unique_id "asbdXrqd9Ii046A6SvhbvAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-07 22:31:50
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:53:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:52:59.580461 2026] [security2:error] [pid 28830:tid 28830] [client 141.101.76.21:11609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "televisonic.com"] [uri "/.env.backup"] [unique_id "asa_O5s8yTTcM8mpvONeiQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-07 21:28:51
(1 day ago)
[mx01aln] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.76.21 - - [07/Oct/2026:23:28:50 +0200] "GET /.env.staging HTTP/1.1" 301 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
141.101.76.21 - - [07/Oct/2026:23:28:50 +0200] "GET /.env.production HTTP/1.1" 301 597 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-07 17:15:50
(1 day ago)
141.101.76.21 - - [07/Oct/2026:17:09:11 +0000] "GET /.git/HEAD HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Win ...
show more
141.101.76.21 - - [07/Oct/2026:17:09:11 +0000] "GET /.git/HEAD HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0" "2a06:98c0:3600::103" edge="141.101.76.21"
141.101.76.21 - - [07/Oct/2026:17:09:13 +0000] "GET /.netrc HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15" "2a06:98c0:3600::103" edge="141.101.76.21"
141.101.76.21 - - [07/Oct/2026:17:09:13 +0000] "GET /.ssh/id_ed25519 HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15" "2a06:98c0:3600::103" edge="141.101.76.21"
141.101.76.21 - - [07/Oct/2026:17:15:27 +0000] "GET /.env.bak HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0" "2a06:98c0:3600::103" edge="141.101.76.21"
141.101.76.21 - - [07/Oct/2026:17:15:28 +0000] "GET /.aws/credentials HTTP/2.0" 403 0 "-
...
show less
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 14:54:24
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 10:08:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:08:25.169445 2026] [security2:error] [pid 1932:tid 1932] [client 141.101.76.21:11173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hardcountryrock.com"] [uri "/wp-config.php.bak"] [unique_id "asYaGRtZSI9r5v7YLexHJAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 09:26:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:26:05.505297 2026] [security2:error] [pid 29263:tid 29263] [client 141.101.76.21:10205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "logicpuzzles.com"] [uri "/.git/HEAD"] [unique_id "asYQLU2gw4lowTZK8qO48AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 04:47:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:47:46.072033 2026] [security2:error] [pid 24222:tid 24222] [client 141.101.76.21:13107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lawrencehale.net"] [uri "/wp-config.php.bak"] [unique_id "asXO8htz-PZvEfNuAF2AtQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 03:39:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:39:47.815615 2026] [security2:error] [pid 5014:tid 5014] [client 141.101.76.21:12237] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "orchestrateyouraptitudes.com"] [uri "/.env.dev"] [unique_id "asW_A4_TNbUowH8UW4_cMAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack