๐บ๐ธ
p0tatosmash3r
2026-10-07 18:19:46
(46 minutes ago)
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration ...
show more
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-10-07 15:30:39
(3 hours ago)
141.101.76.53 - - [07/Oct/2026:12:30:39 -0300] "GET /.git/HEAD HTTP/2.0" 500 572 "-" "Mozilla/5.0 (X ...
show more
141.101.76.53 - - [07/Oct/2026:12:30:39 -0300] "GET /.git/HEAD HTTP/2.0" 500 572 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐จ๐ฆ
Roper123
2026-10-07 13:08:35
(5 hours ago)
Web app exploits
Web App Attack
Anonymous
2026-10-07 11:23:17
(7 hours ago)
2026/10/07 11:23:13 [error] 3693535#3693535: *112974 [client 141.101.76.53] ModSecurity: Access deni ...
show more
2026/10/07 11:23:13 [error] 3693535#3693535: *112974 [client 141.101.76.53] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.30.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yobookz.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "179137219351.113765"] [ref ""], client: 141.101.76.53, server: yobookz.com, request: "GET /.terraform/terraform.tfstate.backup HTTP/2.0", host: "yobookz.com"
2026/10/07 11:23:14 [error] 3693535#3693535: *112974 [client 141.101.76.53] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCOR
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-07 10:08:32
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:08:28.007610 2026] [security2:error] [pid 12628:tid 12628] [client 141.101.76.53:12119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hardcountryrock.com"] [uri "/.env.staging"] [unique_id "asYaHIzyibfoICDk7bs0igAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 02:52:26
(16 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:43:27
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:43:22.306600 2026] [security2:error] [pid 16508:tid 16508] [client 141.101.76.53:12479] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||evolutionmedical.help|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "evolutionmedical.help"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asWxygjMQOtXpvTIXTd6LAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-07 02:38:59
(16 hours ago)
[WedOct0704:38:50.1679532026][security2:error][pid3015779:tid3015803][client141.101.76.53:0]ModSecur ...
show more
[WedOct0704:38:50.1679532026][security2:error][pid3015779:tid3015803][client141.101.76.53:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"4hosts.net\"][uri\"/.env.local\"][unique_id\"asWwulA6JSZ_CvmK40XyqgAAAFY\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 00:17:07
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 20:17:02.459454 2026] [security2:error] [pid 22487:tid 22487] [client 141.101.76.53:9840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "humbliaslaw.com"] [uri "/.env.bak"] [unique_id "asWPfsYFBAbzH73_ViVqnQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 00:03:49
(19 hours ago)
[07/Oct/2026:03:03:46 +0300] -- 141.101.76.53 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[07/Oct/2026:03:03:46 +0300] -- 141.101.76.53 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:40:59
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:40:54.277685 2026] [security2:error] [pid 3081:tid 3081] [client 141.101.76.53:10767] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graficasbis.com"] [uri "/wp-config.php"] [unique_id "asVc1iFPzLxUZxUbpBPQiAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-06 15:41:42
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-10-06 15:15:49
(1 day ago)
vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:49:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:48:55.083661 2026] [security2:error] [pid 28001:tid 28001] [client 141.101.76.53:10219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "images4themind.com"] [uri "/.env.production"] [unique_id "asTuN_WWf4q8iM1CFV6aaQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:02:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:01:55.369839 2026] [security2:error] [pid 24016:tid 24016] [client 141.101.76.53:11513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sparemediagroup.com"] [uri "/wp-config.php.save"] [unique_id "asTVI7nDaMIkjTQeOCWWjgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack