๐ฉ๐ช
Vegascosmetics
2026-10-07 18:31:46
(34 minutes ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 18:17:47
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 14:17:41.525474 2026] [security2:error] [pid 10711:tid 10711] [client 141.101.98.14:13933] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.lindenwoodpark.org"] [uri "/.env.backup"] [unique_id "asaMxWwQa4myu1O5qUgTZQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 14:01:37
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 10:01:30.927579 2026] [security2:error] [pid 11530:tid 11530] [client 141.101.98.14:11570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pseudospace.com"] [uri "/.env"] [unique_id "asZQuntPQ6wAwntYOguWUgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 12:52:55
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:52:52.575722 2026] [security2:error] [pid 26455:tid 26455] [client 141.101.98.14:11278] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidtempleofdeliverance.org|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidtempleofdeliverance.org"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asZApCouxh3Fjqda3K8-6gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 11:21:15
(7 hours ago)
2026/10/07 11:19:10 [error] 3693532#3693532: *112595 [client 141.101.98.14] ModSecurity: Access deni ...
show more
2026/10/07 11:19:10 [error] 3693532#3693532: *112595 [client 141.101.98.14] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.30.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yobookz.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "179137195090.077457"] [ref ""], client: 141.101.98.14, server: yobookz.com, request: "GET /.terraform/terraform.tfstate.backup HTTP/2.0", host: "yobookz.com"
2026/10/07 11:19:11 [error] 3693532#3693532: *112595 [client 141.101.98.14] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCOR
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-07 09:28:12
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:28:06.134238 2026] [security2:error] [pid 29986:tid 29986] [client 141.101.98.14:9910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lidart.org"] [uri "/.env.production"] [unique_id "asYQpq0P4llM4Dd8izXclwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 08:50:06
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 04:50:00.832587 2026] [security2:error] [pid 20621:tid 20621] [client 141.101.98.14:11192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cyprus-boat-registration.com"] [uri "/.env.bak"] [unique_id "asYHuMSVqpAute-f6w397AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 07:58:53
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 03:58:48.714865 2026] [security2:error] [pid 32021:tid 32086] [client 141.101.98.14:9409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotairwelder.com"] [uri "/.htaccess"] [unique_id "asX7uCchYa8Z8ckmuKfDtgAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 22:24:03
(20 hours ago)
WordPress Sensitive System Files Information Disclosure.
Hacking
๐ฌ๐ง
consul.to
2026-10-06 15:53:17
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:53:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:52:57.462692 2026] [security2:error] [pid 6449:tid 6449] [client 141.101.98.14:12321] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehomemailbox.com"] [uri "/wp-config.php.save"] [unique_id "asULSR-IAFPEnRw8kKl_HQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:21:21
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:21:17.373073 2026] [security2:error] [pid 1950799:tid 1950817] [client 141.101.98.14:11914] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adt-sales.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adt-sales.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asT1zXlkd0pOI7-89lM7EwAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-06 13:00:18
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:19:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:19:22.291462 2026] [security2:error] [pid 7091:tid 7091] [client 141.101.98.14:11783] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sigiweb.net"] [uri "/.env.local"] [unique_id "asTnSsgElIXGAYKCH0tuggAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:58:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:58:15.068675 2026] [security2:error] [pid 29978:tid 29978] [client 141.101.98.14:13999] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabbathschoolguide.com"] [uri "/.git/config"] [unique_id "asTiV7eUGJW-q8L124kx3QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack