๐ซ๐ท
dynamix
2026-09-12 10:16:40
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
craudiovizai
2026-09-09 18:30:38
(3 weeks ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-31 08:05:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:05:14.537100 2026] [security2:error] [pid 3391:tid 3391] [client 141.101.97.67:11055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theprairiejewel.com"] [uri "/.git/HEAD"] [unique_id "apU1uu7r9xmqcHk-4IpqOAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 22:26:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 18:26:05.502642 2026] [security2:error] [pid 29293:tid 29293] [client 141.101.97.67:9298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrbaystreet.com"] [uri "/.git/HEAD"] [unique_id "apNcfXSpNVxFb-JNovCTDQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 15:16:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 11:16:17.351465 2026] [security2:error] [pid 23071:tid 23071] [client 141.101.97.67:12541] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cbsproductionsinc.com"] [uri "/.git/config"] [unique_id "apL3wccwy08h4u2g_ZngmgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 12:42:54
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:42:46.707625 2026] [security2:error] [pid 32168:tid 32193] [client 141.101.97.67:13911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ccgparquitectos.com"] [uri "/.git/config"] [unique_id "apLTxpguVAy3ifJPDEnxIAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 11:52:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:52:14.024782 2026] [security2:error] [pid 4259:tid 4259] [client 141.101.97.67:9401] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sushamalka.royal-barbershop.com"] [uri "/.git/config"] [unique_id "apLH7ucesGA0Weqhk03CrgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:17:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:17:15.299498 2026] [security2:error] [pid 12107:tid 12107] [client 141.101.97.67:9805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.skotam.com"] [uri "/.git/config"] [unique_id "apFuO_39JK8QrvXBhhUrEAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 11:18:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:18:36.986702 2026] [security2:error] [pid 29840:tid 29840] [client 141.101.97.67:10024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.conveyorizedovens.com"] [uri "/.git/config"] [unique_id "ao7LjF4Spi1NygZhB8oqYwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-25 10:09:31
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2026-08-24 11:13:32
(1 month ago)
141.101.97.67 - - [24/Aug/2026:13:13:29 +0200] "GET /%252factuator%252fhealth HTTP/1.1" 403 124 "-" ...
show more
141.101.97.67 - - [24/Aug/2026:13:13:29 +0200] "GET /%252factuator%252fhealth HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.67 - - [24/Aug/2026:13:13:29 +0200] "GET /%252factuator%252flogfile HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.67 - - [24/Aug/2026:13:13:29 +0200] "GET /%252fadmin%252ehtml HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.67 - - [24/Aug/2026:13:13:29 +0200] "GET /%252fadmin%252f.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.67 - - [24/Aug/2026:13:13:29 +0200] "GET /%252fadmin%252fconsole%252f.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.67 - - [24/Aug/2026:13:13:30 +0200] "GET /%252fadmin%252fphp-info.php HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.67 - - [24/Aug/2026:13:13:30 +0200] "GET /%252fadmin%252fphp_info.php HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.67 - - [24/Aug/2026:13:13:30 +0200] "GET /%252fadministrator%252f.env HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.67 - - [24/Aug/2026:13:13:30 +0200] "GET /%252fadministrator%252finfo.php HTTP
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-22 21:59:06
(1 month ago)
Auto-ban: >3000 req/min op 2026-08-22
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-21 11:07:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 07:07:03.138587 2026] [security2:error] [pid 24583:tid 24615] [client 141.101.97.67:11015] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mjkotob.com"] [uri "/.git/HEAD"] [unique_id "aogxV4syI90i6bF3QvSnJAAAAdE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 00:33:43
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 20:33:36.135413 2026] [security2:error] [pid 12022:tid 12022] [client 141.101.97.67:13881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.drlaurengardner.com"] [uri "/.git/config"] [unique_id "aoec4PO5AqcP94qrklq1ngAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 18:21:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 14:21:17.603047 2026] [security2:error] [pid 807:tid 807] [client 141.101.97.67:11418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fractalistic.gregorii.com"] [uri "/.git/HEAD"] [unique_id "aodFnTFAnZzrZyvNaMQKAQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack