π©πͺ
wpadm4
2026-10-02 22:24:00
(6 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π«π·
dynamix
2026-10-02 16:30:15
(12 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 14:26:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:26:29.825472 2026] [security2:error] [pid 14699:tid 14699] [client 141.101.76.51:11985] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blackoakprop.com"] [uri "/.svn/entries"] [unique_id "ar5tlSDGWz7sYpcI-QksMgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-01 06:36:27
(1 day ago)
[01/Oct/2026:09:36:26 +0300] -- 141.101.76.51 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[01/Oct/2026:09:36:26 +0300] -- 141.101.76.51 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 05:32:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:32:17.738866 2026] [security2:error] [pid 29766:tid 29766] [client 141.101.76.51:12142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.genesis-castle.com"] [uri "/.env.staging"] [unique_id "ar3wYWJnyuliz1DB8nxnxwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-09-30 22:48:35
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, git_exposure, ssh_keys. Observed by 1 sensor(s); 6 hits.
show less
Web App Attack
π©πͺ
Bedios GmbH
2026-09-30 16:33:04
(2 days ago)
Login credentials theft attempt
Hacking
π«π·
dynamix
2026-09-30 16:30:49
(2 days ago)
Multiple WAF Violations
Web App Attack
π©πͺ
Lino Project
2026-09-30 13:26:22
(2 days ago)
141.101.76.51 - - [30/Sep/2026:15:26:21 +0200] "GET /config.json HTTP/2.0" 403 0 "-" "Mozilla/5.0 (W ...
show more
141.101.76.51 - - [30/Sep/2026:15:26:21 +0200] "GET /config.json HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 09:29:59
(2 days ago)
apache vulnerability scan
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-30 05:27:01
(2 days ago)
[30/Sep/2026:08:27:00 +0300] -- 141.101.76.51 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[30/Sep/2026:08:27:00 +0300] -- 141.101.76.51 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 04:40:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:40:25.524876 2026] [security2:error] [pid 2048:tid 2048] [client 141.101.76.51:11038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.boat-registration-croatia.com"] [uri "/.env.staging"] [unique_id "arySuTUdSNSa-WtKcPIm4QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 03:43:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:43:52.990681 2026] [security2:error] [pid 6141:tid 6141] [client 141.101.76.51:9987] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.modelengines.info"] [uri "/.svn/entries"] [unique_id "aryFeKeudlzG0RZJGmBM8AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 03:20:35
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:20:32.752347 2026] [security2:error] [pid 21264:tid 21264] [client 141.101.76.51:9477] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.partybussantafe.com"] [uri "/wp-config.php.bak"] [unique_id "aryAAI787ezHCqZxkHyV6AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 19:35:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.51 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:35:19.480961 2026] [security2:error] [pid 18684:tid 18684] [client 141.101.76.51:12531] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.garantaconsulting.com"] [uri "/.env.production"] [unique_id "arwS98NEmBWXODKPqBuSqQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack