๐บ๐ธ
TPI-Abuse
2026-10-07 13:30:26
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 09:30:22.822675 2026] [security2:error] [pid 18085:tid 18111] [client 141.101.76.33:9249] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amphoracollectors.org"] [uri "/wp-config.php"] [unique_id "asZJbmOX11bbU823Hgek7QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 13:10:11
(43 minutes ago)
141.101.76.33 - - [07/Oct/2026:10:10:06 -0300] "GET /.htaccess HTTP/2.0" 403 1110 "-" "Mozilla/5.0 ( ...
show more
141.101.76.33 - - [07/Oct/2026:10:10:06 -0300] "GET /.htaccess HTTP/2.0" 403 1110 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
141.101.76.33 - - [07/Oct/2026:10:10:10 -0300] "GET /wp-config.php HTTP/1.1" 404 1129 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Port Scan
๐บ๐ธ
craudiovizai
2026-10-07 12:30:46
(1 hour ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-07 12:27:17
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:27:10.652340 2026] [security2:error] [pid 9142:tid 9142] [client 141.101.76.33:12023] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/wp-config.php.old"] [unique_id "asY6nlLlQchZvUryX_RnRAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 12:13:22
(1 hour ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 05:11:33
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:11:27.803211 2026] [security2:error] [pid 21446:tid 21446] [client 141.101.76.33:12952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffautry.com"] [uri "/.git/HEAD"] [unique_id "asXUfw0332nK0XK3aBowwgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 03:16:38
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:16:33.381453 2026] [security2:error] [pid 1279:tid 1283] [client 141.101.76.33:11309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotairwelder.com"] [uri "/.git/config"] [unique_id "asW5kSLA1cnrRhwk9MuV0AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:04:40
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:04:33.773654 2026] [security2:error] [pid 32329:tid 32329] [client 141.101.76.33:13078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "humbliaslaw.com"] [uri "/wp-config.php"] [unique_id "asV-gXMLwGXxAgReOhealQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:23:11
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:22:56.450090 2026] [security2:error] [pid 9959:tid 9959] [client 141.101.76.33:13387] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greed.ee"] [uri "/.env.bak"] [unique_id "asUgYHLOM1CnZVA9fb9UBwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-06 16:06:00
(21 hours ago)
[06/Oct/2026:19:05:59 +0300] -- 141.101.76.33 Ban reason: Scanner [CMS_GENERIC] | Request: GET /conf ...
show more
[06/Oct/2026:19:05:59 +0300] -- 141.101.76.33 Ban reason: Scanner [CMS_GENERIC] | Request: GET /config.php HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:25:01
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:24:50.977264 2026] [security2:error] [pid 25769:tid 25769] [client 141.101.76.33:12747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ptr.dutchlake.com"] [uri "/.env.backup"] [unique_id "asUSwnz-0yMTLuqFFetgUgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:37:44
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:37:39.835375 2026] [security2:error] [pid 16357:tid 16357] [client 141.101.76.33:13555] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bikiniwatersports.com"] [uri "/.htaccess"] [unique_id "asUHs9Z4ktlLkBJC1229ewAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:00:32
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:00:26.341072 2026] [security2:error] [pid 8630:tid 8630] [client 141.101.76.33:12923] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cityofhaleyville.com"] [uri "/.env.local"] [unique_id "asT--gELApFx7FTFba3gvQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:38:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:38:39.428763 2026] [security2:error] [pid 13539:tid 13539] [client 141.101.76.33:10022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "askegroup.com"] [uri "/wp-config.php.old"] [unique_id "asT539dFIbnOB4WNCziYYQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:44:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:44:49.065394 2026] [security2:error] [pid 12436:tid 12436] [client 141.101.76.33:12187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desertalfas.org"] [uri "/wp-config.php.save"] [unique_id "asTtQQlKyElV47stWn0E7wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack