๐บ๐ธ
TPI-Abuse
2026-10-01 16:06:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:06:13.123968 2026] [security2:error] [pid 13939:tid 13939] [client 141.101.98.116:14225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bizzybeejunkremoval.com"] [uri "/.env"] [unique_id "ar6E9WiVR4M8NCUE-TqP-AAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-09-30 19:18:44
(1 day ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-09-30 17:14:50
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:28:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:28:20.020983 2026] [security2:error] [pid 13961:tid 13961] [client 141.101.98.116:10910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "janton.com"] [uri "/.env"] [unique_id "ar0qlAFQszvTUev-9RcICAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:12:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:12:45.036835 2026] [security2:error] [pid 9083:tid 9083] [client 141.101.98.116:10084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rldcompany.com"] [uri "/.env.local"] [unique_id "arz8vXsvUEWBv97Lsu_mvAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
Jim Keir
2026-09-30 09:27:43
(2 days ago)
2026-09-30 09:27:43 141.101.98.116 File scanning, blocking 141.101.98.116 for 5 minutes
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-30 08:31:14
(2 days ago)
[30/Sep/2026:11:31:14 +0300] -- 141.101.98.116 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[30/Sep/2026:11:31:14 +0300] -- 141.101.98.116 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-30 05:14:33
(2 days ago)
7 attacks on env grabbing URLs, password/key grabbing URLs, config grabbing URLs (type 2), PHP URLs, ...
show more
7 attacks on env grabbing URLs, password/key grabbing URLs, config grabbing URLs (type 2), PHP URLs, VC URLs:
GET /.env.local HTTP/1.1
GET /.ssh/id_rsa HTTP/1.1
GET /config.json HTTP/1.1
GET /config.php HTTP/1.1
GET /.git/config HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-09-30 04:32:13
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ท๐บ
OK
2026-09-30 04:05:07
(2 days ago)
HTTP/HTTPS
Hacking
Web App Attack
๐ฎ๐น
Inartis
2026-09-30 03:24:25
(2 days ago)
141.101.98.116 - - [30/Sep/2026:05:24:16 +0200] "GET /.env.backup HTTP/1.1" 301 5262 "-" "Mozilla/5. ...
show more
141.101.98.116 - - [30/Sep/2026:05:24:16 +0200] "GET /.env.backup HTTP/1.1" 301 5262 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
141.101.98.116 - - [30/Sep/2026:05:24:24 +0200] "GET /.env HTTP/1.1" 301 5262 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
141.101.98.116 - - [30/Sep/2026:05:24:24 +0200] "GET /.env.staging HTTP/1.1" 301 5262 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
debaba
2026-09-30 00:54:34
(2 days ago)
aktiv
[30/Sep/2026:00:54:25.863183 +0000] arxdwTil7wM94XZ3yJn6dgAAAAY 141.101.98.116 43374 127.0.0.1 ...
show more
aktiv
[30/Sep/2026:00:54:25.863183 +0000] arxdwTil7wM94XZ3yJn6dgAAAAY 141.101.98.116 43374 127.0.0.1 7081
[30/Sep/2026:00:54:26.050541 +0000] arxdweoi_ccUvq
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 15:08:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 11:07:53.582665 2026] [security2:error] [pid 19112:tid 19112] [client 141.101.98.116:12305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.magnoliahillproductions.com"] [uri "/.env.local"] [unique_id "arvUSWInb53U2ySfJM1pFQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 12:12:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:12:12.521704 2026] [security2:error] [pid 22462:tid 22462] [client 141.101.98.116:13204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.acatucson.com"] [uri "/.env.backup"] [unique_id "arurHMaA9d14i1aDqz00fwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 10:36:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:36:50.872939 2026] [security2:error] [pid 6988:tid 6988] [client 141.101.98.116:9458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stoneybluff.com"] [uri "/.env"] [unique_id "aruUwvt-ihVlUiHUOwRJxAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack