πΊπΈ
TPI-Abuse
2026-10-06 02:55:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 22:55:38.614335 2026] [security2:error] [pid 10747:tid 10747] [client 141.101.76.70:10484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.achildsspace.com"] [uri "/.env.dev"] [unique_id "asRjKmGXh65-x8mmIjiV4QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 00:04:46
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 20:04:40.755450 2026] [security2:error] [pid 12952:tid 12952] [client 141.101.76.70:12837] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daassociatesllc.com"] [uri "/.htaccess"] [unique_id "asQ7GKhDDloPoPESBM01yAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 22:50:06
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:49:53.102527 2026] [security2:error] [pid 27922:tid 27922] [client 141.101.76.70:10085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathewyoung.com"] [uri "/wp-config.php.old"] [unique_id "asQpkURbGL7uWrKtwkFllQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
masterguru
2026-10-05 21:49:58
(6 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
π«π·
dynamix
2026-10-05 21:34:04
(6 hours ago)
Multiple WAF Violations
Web App Attack
π©πͺ
altenglaner
2026-10-05 09:04:57
(19 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
π«π·
arsonist
2026-10-05 08:49:34
(19 hours ago)
[fail2ban]
2026-10-05T08:49:34.115183+00:00 arson caddy[1712]: {"level":"info","ts":1791190174.11515 ...
show more
[fail2ban]
2026-10-05T08:49:34.115183+00:00 arson caddy[1712]: {"level":"info","ts":1791190174.1151552,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"141.101.76.70","remote_port":"11339","client_ip":"141.101.76.70","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/cache/original/%2e%2e/.env","headers":{"Accept":["*/*"],"Cf-Ray":["a45b2c7c2bddf5dc-AMS"],"Cf-Connecting-Ip":["34.187.105.22"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"Cdn-Loop":["cloudflare; loops=1"],"Cf-Ipcountry":["NL"],"User-Agent":["Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"X-Forwarded-Proto":["https"],"X-Forwarded-For":["34.187.105.22"],"Accept-Encod
...
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-05 08:38:34
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 04:38:28.319999 2026] [security2:error] [pid 28616:tid 28616] [client 141.101.76.70:11747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "googhoo.com"] [uri "/.env.backup"] [unique_id "asNiBDnCNcCU-jVAYDFJgwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-04 08:29:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 04:29:36.249264 2026] [security2:error] [pid 8158:tid 8158] [client 141.101.76.70:11562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foundintranslation.net"] [uri "/.env.local"] [unique_id "asIOcNlS7FiRWKVs06yDAAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-04 00:06:42
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-10-01 17:28:47
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:28:40.670288 2026] [security2:error] [pid 18889:tid 18889] [client 141.101.76.70:10581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.partyblockparties.com"] [uri "/.env"] [unique_id "ar6YSDt8k_qyZKNHAfirYgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Bedios GmbH
2026-10-01 13:30:09
(4 days ago)
Login credentials theft attempt
Hacking
π―π΅
VXG-NET
2026-10-01 12:40:24
(4 days ago)
port=80, indicator_type=info-leak
Hacking
π³π±
BlueWire Hosting
2026-10-01 12:33:16
(4 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 09:45:00
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:44:50.209131 2026] [security2:error] [pid 14448:tid 14448] [client 141.101.76.70:9429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "templehistorical.org"] [uri "/.env.staging"] [unique_id "ar4rkoXoMnZWDVkmAQdbQwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack