๐ฉ๐ช
on-com
2026-10-01 19:31:10
(56 minutes ago)
URL scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 06:31:40
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:31:36.348115 2026] [security2:error] [pid 30634:tid 30711] [client 141.101.76.44:9835] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rockabyecotons.com"] [uri "/.env"] [unique_id "ar3-SNAwr-QxBCFxKbhjiQAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
David Koswari
2026-10-01 05:41:00
(14 hours ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐ซ๐ท
giulio gorobey
2026-10-01 05:40:18
(14 hours ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-config.php
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-01 05:19:56
(15 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-01 03:01:53
(17 hours ago)
[01/Oct/2026:06:01:53 +0300] -- 141.101.76.44 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[01/Oct/2026:06:01:53 +0300] -- 141.101.76.44 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-30 20:59:00
(23 hours ago)
141.101.76.44 - - [30/Sep/2026:22:58:58 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 615 "-" "Mozill ...
show more
141.101.76.44 - - [30/Sep/2026:22:58:58 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 615 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
141.101.76.44 - - [30/Sep/2026:22:58:17 +0200] "GET /.env.local HTTP/1.1" 301 601 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
141.101.76.44 - - [30/Sep/2026:22:58:25 +0200] "GET /.env HTTP/1.1" 301 589 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
141.101.76.44 - - [30/Sep/2026:22:58:25 +0200] "GET /.env.local HTTP/1.1" 301 601 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
141.101.76.44 - - [30/Sep/2026:22:58:33 +0200] "GET /.svn/entries HTTP/1.1" 301 605 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
141.101.76.44 - - [30/Sep/2
show less
Web App Attack
Brute-Force
๐ช๐ธ
el-brujo
2026-09-30 20:48:19
(23 hours ago)
30/Sep/2026:22:48:18.459328 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
30/Sep/2026:22:48:18.459328 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 141.101.76.44] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "parrot.elhacker.net"] [uri "/.env"] [unique_id "ar11kp5kBvD58ZuRLi-W7AAFLEI"]
...
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-30 20:10:51
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
claude CALVET
2026-09-30 15:22:58
(1 day ago)
gee-17 : Block hidden directories=>/.env.local(/)
Hacking
Anonymous
2026-09-30 14:47:21
(1 day ago)
GET /.env.staging HTTP/1.1
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:36:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:36:46.305068 2026] [security2:error] [pid 20479:tid 20479] [client 141.101.76.44:9286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.konahawaii.com"] [uri "/wp-config.php.bak"] [unique_id "arz0Tre2VIpOAikPjDjdJQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 08:36:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 04:36:12.522910 2026] [security2:error] [pid 4646:tid 4646] [client 141.101.76.44:11341] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.littlehornengineering.com"] [uri "/.git/config"] [unique_id "arzJ_EVQmUAlGl2IsttOhwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 08:18:37
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 141.101.76.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.76.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 04:18:32.280919 2026] [security2:error] [pid 15102:tid 15102] [client 141.101.76.44:12616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hendersonhomes.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hendersonhomes.com"] [uri "/index.php.bak"] [unique_id "arzF2JlPHNJ8vIQkqkTnswAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 06:55:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:55:34.488519 2026] [security2:error] [pid 8846:tid 8846] [client 141.101.76.44:9572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.polishedspaservices.com"] [uri "/.env.backup"] [unique_id "aryyZkgZMedj5ksxHpQ-oAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack