๐บ๐ธ
TPI-Abuse
2026-08-26 10:40:26
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:40:21.250001 2026] [security2:error] [pid 5243:tid 5243] [client 141.101.97.34:9886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.theknowledgemaster.com"] [uri "/.git/HEAD"] [unique_id "ao7ClWoUwIi-HvfX6dv22wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-25 15:00:00
(1 day ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-25 13:13:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 09:13:39.812671 2026] [security2:error] [pid 22847:tid 22847] [client 141.101.97.34:12164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.theholleys.net"] [uri "/.git/HEAD"] [unique_id "ao2VAzOok6n_VrSkPYWZKwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 11:14:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:13:57.065946 2026] [security2:error] [pid 21914:tid 21914] [client 141.101.97.34:10826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rodrandolph.com"] [uri "/.git/HEAD"] [unique_id "aowndR8FKCC6_Mh3JscNfAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 10:21:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 06:21:09.951413 2026] [security2:error] [pid 12215:tid 12215] [client 141.101.97.34:9887] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.travelto.info"] [uri "/.git/HEAD"] [unique_id "aowbFSfbKRTThwln5PEw0gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
0x44
2026-08-24 07:13:46
(2 days ago)
Abusive host detected - Attempt to access sensitive files
Web App Attack
Hacking
๐ง๐ช
madeit
2026-08-22 09:32:26
(4 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:35:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:35:35.809980 2026] [security2:error] [pid 17032:tid 17032] [client 141.101.97.34:10948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.integritysecurity.us"] [uri "/.git/HEAD"] [unique_id "aoFaNzlB-FPgpwqA6vFGEwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-06 14:17:23
(2 weeks ago)
Web App Attack
๐ฌ๐ง
OptimusGO
2026-08-02 18:55:13
(3 weeks ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-02 19:55:13 UTC
Log evidence:
141.101.97.34 - - [02/Aug/2026:19:55:11 +0100] "GET /staging/config/constants%2ejs HTTP/1.1" 404 118 "-" "curl/8.7.1"
08/02/2026-19:55:11.628024 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 141.101.97.34:9724 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐บ๐ธ
mawan
2026-07-02 20:15:51
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-28 22:02:55
(1 month ago)
Auto-ban: >3000 req/min op 2026-06-28
Web App Attack
SSH
Hacking
๐ฌ๐ง
OptimusGO
2026-06-21 02:32:46
(2 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-21 03:32:46 UTC
Log evidence:
141.101.97.34 - - [21/Jun/2026:03:32:46 +0100] "GET /config/pnpm%2ejs HTTP/1.1" 404 118 "-" "curl/8.7.1"
06/21/2026-03:32:46.310159 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 141.101.97.34:11534 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐บ๐ธ
freeutka
2026-05-15 03:56:02
(3 months ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐ฉ๐ช
www.mammazone.it
2026-05-13 09:18:02
(3 months ago)
fabiodirauso.it:443 141.101.97.34 - - [13/May/2026:11:17:43 +0200] "GET /config/test/config%2eini HT ...
show more
fabiodirauso.it:443 141.101.97.34 - - [13/May/2026:11:17:43 +0200] "GET /config/test/config%2eini HTTP/1.1" 200 20100 "-" "curl/8.7.1"
fabiodirauso.it:443 141.101.97.34 - - [13/May/2026:11:18:00 +0200] "GET /backup/database%2eyml HTTP/1.1" 200 20097 "-" "curl/8.7.1"
...
show less
Hacking