๐บ๐ธ
TPI-Abuse
2026-08-28 21:18:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:18:54.126712 2026] [security2:error] [pid 16735:tid 16735] [client 141.101.97.72:12306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flymarlin.com"] [uri "/.git/config"] [unique_id "apH7Ps_pjIqjW5HrWsDHPgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 20:52:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:52:21.867622 2026] [security2:error] [pid 27352:tid 27352] [client 141.101.97.72:10694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.qovintheloop.org"] [uri "/.git/config"] [unique_id "apH1BdOrRUMaCC7JC8R0PwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 19:38:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:38:24.881009 2026] [security2:error] [pid 11180:tid 11254] [client 141.101.97.72:11574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.inal.org"] [uri "/.git/config"] [unique_id "apHjsGs8C3ae6sbrOZbbsgAAAlA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:29:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:28:59.463412 2026] [security2:error] [pid 13183:tid 13183] [client 141.101.97.72:12327] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "njletr.org"] [uri "/.git/HEAD"] [unique_id "ao8wa2NSJHFhJ2b4Cosl0wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 09:31:35
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:31:26.869801 2026] [security2:error] [pid 31262:tid 31262] [client 141.101.97.72:12364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rdkrecords.com"] [uri "/.git/HEAD"] [unique_id "ao6ybggm1_1NNmADJPq5gAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-26 08:33:33
(4 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 03:46:39
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 23:46:35.660658 2026] [security2:error] [pid 9841:tid 9841] [client 141.101.97.72:10457] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jordanware.com"] [uri "/.git/config"] [unique_id "ao0QG6cDYcWVd_sqfhBY_gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 02:55:29
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 22:55:23.324873 2026] [security2:error] [pid 28149:tid 28149] [client 141.101.97.72:11437] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vittaria.vittariadesign.com"] [uri "/.git/config"] [unique_id "ao0EGxULoYr_lknZSrGpvgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-24 22:01:12
(5 days ago)
Auto-ban: >3000 req/min op 2026-08-24
Web App Attack
SSH
Hacking
๐ฉ๐ช
inlink.ltd
2026-08-24 20:52:25
(5 days ago)
dot file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 08:25:04
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.97.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 04:24:56.882852 2026] [security2:error] [pid 23429:tid 23429] [client 141.101.97.72:10934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cynosure.email"] [uri "/.git/HEAD"] [unique_id "aov_2CYgFjZXzDiwAI0-oQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-13 13:28:12
(2 weeks ago)
141.101.97.72 - - [13/Aug/2026:15:28:09 +0200] "GET /.git/refs/tags HTTP/1.1" 403 124 "-" "curl/8.7. ...
show more
141.101.97.72 - - [13/Aug/2026:15:28:09 +0200] "GET /.git/refs/tags HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.72 - - [13/Aug/2026:15:28:09 +0200] "GET /.git/objects HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.72 - - [13/Aug/2026:15:28:09 +0200] "GET /.git/packed-refs HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.72 - - [13/Aug/2026:15:28:10 +0200] "GET /.git/description HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.72 - - [13/Aug/2026:15:28:10 +0200] "GET /.git/info HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.72 - - [13/Aug/2026:15:28:10 +0200] "GET /.git/info/exclude HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.72 - - [13/Aug/2026:15:28:10 +0200] "GET /.git/hooks HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.72 - - [13/Aug/2026:15:28:10 +0200] "GET /.git/COMMIT_EDITMSG HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.72 - - [13/Aug/2026:15:28:10 +0200] "GET /.git/FETCH_HEAD HTTP/1.1" 403 124 "-" "curl/8.7.1"
141.101.97.72 - - [13/Aug/2026:15:28:10 +0200] "GET /.git/ORIG_HEAD HTT
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-07-22 01:19:52
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฌ๐ง
OptimusGO
2026-07-16 01:14:42
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-16 02:14:42 UTC
Log evidence:
141.101.97.72 - - [16/Jul/2026:02:14:38 +0100] "GET /config/production%2ejs HTTP/1.1" 404 118 "-" "curl/8.7.1"
07/16/2026-02:14:38.533285 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 141.101.97.72:10003 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐ฒ๐ฝ
octageeks.com
2026-07-08 04:09:44
(1 month ago)
Wordpress malicious attack:[octaflood]
Web App Attack