πΊπΈ
TPI-Abuse
2026-10-01 11:49:32
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:49:26.990781 2026] [security2:error] [pid 19624:tid 19624] [client 141.101.98.139:12735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1214productions.com"] [uri "/.env.backup"] [unique_id "ar5Ixu_ptwneKMVpDVJPqAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Roderic
2026-10-01 09:18:55
(21 hours ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted])
Port Scan
πΊπΈ
TPI-Abuse
2026-10-01 05:05:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:05:44.627284 2026] [security2:error] [pid 8145:tid 8145] [client 141.101.98.139:11695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hope4elsalvador.org"] [uri "/.svn/entries"] [unique_id "ar3qKGBjbfGpw8J3BD9BUgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FD-IX
2026-10-01 03:29:44
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
π©πͺ
DEV-DNS
2026-09-30 23:55:21
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-30 14:38:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:38:28.753699 2026] [security2:error] [pid 21484:tid 21484] [client 141.101.98.139:14204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thepartyblock.com"] [uri "/.env.staging"] [unique_id "ar0e5Hn0pDM22-_r3UW3SwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 13:05:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:05:20.450942 2026] [security2:error] [pid 22510:tid 22510] [client 141.101.98.139:13162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digifonics.com"] [uri "/.env.local"] [unique_id "ar0JEEiOvRVDH1HdkYQ7sQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 11:56:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:56:34.576529 2026] [security2:error] [pid 416:tid 416] [client 141.101.98.139:12533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cook-islands-boat-registration.com"] [uri "/.env.local"] [unique_id "arz48pYI8JNaLwsZJyTQ3gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 10:59:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:59:39.123232 2026] [security2:error] [pid 9631:tid 9670] [client 141.101.98.139:14100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.worldecom.org"] [uri "/.env.staging"] [unique_id "arzrmwq7nAv2XBxud_fvSQAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
robotstxt
2026-09-29 21:22:06
(2 days ago)
141.101.98.139 - - [29/Sep/2026:21:21:05 +0000] "GET /.env.staging HTTP/2.0" 403 26509 "-" "Mozilla/ ...
show more
141.101.98.139 - - [29/Sep/2026:21:21:05 +0000] "GET /.env.staging HTTP/2.0" 403 26509 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0" "2a06:98c0:3600::103" edge="141.101.98.139"
141.101.98.139 - - [29/Sep/2026:21:21:11 +0000] "GET /.git/HEAD HTTP/2.0" 403 26509 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1" "2a06:98c0:3600::103" edge="141.101.98.139"
141.101.98.139 - - [29/Sep/2026:21:21:14 +0000] "GET /.env.backup HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1" "2a06:98c0:3600::103" edge="141.101.98.139"
141.101.98.139 - - [29/Sep/2026:21:21:19 +0000] "GET /.aws/credentials HTTP/2.0" 403 26509 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0" "2a06:98c0:3600::103" edge="141.101.98.139"
141.101.98.139 - -
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 17:25:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:25:24.861821 2026] [security2:error] [pid 29290:tid 29290] [client 141.101.98.139:12610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mymuscles.com"] [uri "/.env"] [unique_id "arv0hB7FJy_MO89bBvZzNwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 10:36:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:36:31.969908 2026] [security2:error] [pid 1624:tid 1624] [client 141.101.98.139:14211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "todi.org"] [uri "/.env.local"] [unique_id "aruUr2AcfdRxeSfv9IaX8wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-29 02:10:58
(3 days ago)
[29/Sep/2026:05:10:57 +0300] -- 141.101.98.139 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[29/Sep/2026:05:10:57 +0300] -- 141.101.98.139 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 00:32:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:32:13.933744 2026] [security2:error] [pid 10666:tid 10666] [client 141.101.98.139:10944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitality-webb.com"] [uri "/.env.backup"] [unique_id "arsHDdoZ5NDjVvVSvp0d1QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-09-28 21:59:56
(3 days ago)
Auto-ban: >3000 req/min op 2026-09-28
Web App Attack
SSH
Hacking