๐ฉ๐ช
webko.si
2026-09-30 11:04:18
(3 hours ago)
pridenmozic.si: Bruteforce web app access, URI detail: '/.git/config'.
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 21:52:45
(17 hours ago)
[30/Sep/2026:00:52:44 +0300] -- 141.101.98.128 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[30/Sep/2026:00:52:44 +0300] -- 141.101.98.128 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-09-29 21:19:11
(17 hours ago)
Probing for .env file:
141.101.98.128 - - [29/Sep/2026:23:19:07 +0200] "GET /.env.backup HTTP/2.0" 4 ...
show more
Probing for .env file:
141.101.98.128 - - [29/Sep/2026:23:19:07 +0200] "GET /.env.backup HTTP/2.0" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:49:19
(19 hours ago)
(mod_security) mod_security (id:949110) triggered by 141.101.98.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 141.101.98.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:49:15.382498 2026] [security2:error] [pid 26043:tid 26043] [client 141.101.98.128:12632] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "akistech.com"] [uri "/.env.local"] [unique_id "arwWO9lbEPwb7_hSxHNrWgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 10:43:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:43:40.392194 2026] [security2:error] [pid 26702:tid 26770] [client 141.101.98.128:12171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.annybelle.org"] [uri "/.env.backup"] [unique_id "aruWXJE36hnmISwNL4a6NQAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 05:59:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 01:59:03.309408 2026] [security2:error] [pid 18541:tid 18541] [client 141.101.98.128:12064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.joeordie.com"] [uri "/.env"] [unique_id "artTp83K1C1OQxrl3U4rXwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-28 19:00:22
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-28 15:57:08
(1 day ago)
[28/Sep/2026:18:57:07 +0300] -- 141.101.98.128 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[28/Sep/2026:18:57:07 +0300] -- 141.101.98.128 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.staging HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-09-27 11:20:32
(3 days ago)
/wp-content/plugins/woocommerce/readme.txt
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-09-26 14:17:14
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 12:07:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 08:06:59.822381 2026] [security2:error] [pid 2728:tid 2728] [client 141.101.98.128:9802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wryemusings.com"] [uri "/.env.staging"] [unique_id "are1Y2Lnw6QQAQC17DhgjgAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-09-26 10:55:15
(4 days ago)
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kinesk ...
show more
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kineskinja)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 09:56:15
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 05:56:08.864596 2026] [security2:error] [pid 3265:tid 3265] [client 141.101.98.128:13075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.misterflores.com"] [uri "/.env.staging"] [unique_id "areWuLjLhh1ezclHEWX4agAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-17 23:24:36
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-12 00:29:15
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack