๐ฉ๐ช
altenglaner
2026-10-11 03:28:35
(40 minutes ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-11 00:18:04
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-10-10 19:31:16
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 10:23:01
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 06:22:55.849465 2026] [security2:error] [pid 4259:tid 4259] [client 141.101.98.131:12774] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pattymoorearmstrong.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pattymoorearmstrong.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asoR_1OWupDhXJ1jympVawAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-10 07:17:32
(20 hours ago)
141.101.98.131 - - [10/Oct/2026:07:16:31 +0000] "GET /.svn/entries HTTP/2.0" 403 0 "-" "Mozilla/5.0 ...
show more
141.101.98.131 - - [10/Oct/2026:07:16:31 +0000] "GET /.svn/entries HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1" "2a06:98c0:3600::103" edge="141.101.98.131"
141.101.98.131 - - [10/Oct/2026:07:16:31 +0000] "GET /.terraform/terraform.tfstate.backup HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="141.101.98.131"
141.101.98.131 - - [10/Oct/2026:07:16:31 +0000] "GET /.npmrc HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="141.101.98.131"
141.101.98.131 - - [10/Oct/2026:07:16:32 +0000] "GET /wp-config.php.old HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E14
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-09 23:11:52
(1 day ago)
[10/Oct/2026:02:11:51 +0300] -- 141.101.98.131 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[10/Oct/2026:02:11:51 +0300] -- 141.101.98.131 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 22:52:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 18:52:41.862563 2026] [security2:error] [pid 8320:tid 8320] [client 141.101.98.131:12749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "islandsuperbook.net"] [uri "/.env.dev"] [unique_id "aslwOWg_eUtNLh5GfxTovQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 08:28:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 04:28:13.217784 2026] [security2:error] [pid 26124:tid 26124] [client 141.101.98.131:10137] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cassialifesci.com"] [uri "/.git/HEAD"] [unique_id "asilnfSDRc298J1FytMMcQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RamSet
2026-10-09 01:01:25
(2 days ago)
[ycr] HTTP-Probe on port 443 (via domain). 5 distinct paths probed in 3s. Sustained 6 req/min, 4 non ...
show more
[ycr] HTTP-Probe on port 443 (via domain). 5 distinct paths probed in 3s. Sustained 6 req/min, 4 nonexistent paths (404). Paths: /.env.staging, /.env.backup, /.ssh/id_ed25519, /.htaccess
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-08 15:12:19
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 13:52:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:51:59.853050 2026] [security2:error] [pid 19687:tid 19687] [client 141.101.98.131:9670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "donnathedoglady.com"] [uri "/.env.save"] [unique_id "asef_9CXcJyc4kcXCzYs9gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 13:20:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:20:02.309737 2026] [security2:error] [pid 1877:tid 1877] [client 141.101.98.131:12532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.havilahmalone.com"] [uri "/.env.backup"] [unique_id "aseYggF5tKYmLgJ19reLcwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 12:44:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 08:44:11.238090 2026] [security2:error] [pid 15919:tid 15919] [client 141.101.98.131:12533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "texassportsmansassociation.org"] [uri "/.env"] [unique_id "aseQG-Gng2FV8oAcXEQrLgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-08 11:06:00
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 09:40:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:39:59.448901 2026] [security2:error] [pid 14713:tid 14713] [client 141.101.98.131:10473] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ampstudio.eu"] [uri "/.env.local"] [unique_id "asdk7yjIYrSklvo456SX3AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack