๐บ๐ธ
TPI-Abuse
2026-10-10 02:12:20
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 22:12:11.776114 2026] [security2:error] [pid 7271:tid 7271] [client 141.101.98.140:14064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "literarylights.com"] [uri "/.env"] [unique_id "asme-9lXNo2zCMDP0528FAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 23:36:16
(23 hours ago)
GET /.env.dev HTTP/1.1
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 13:29:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 09:29:35.897546 2026] [security2:error] [pid 14462:tid 14462] [client 141.101.98.140:11891] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inetbrain.com"] [uri "/.env.save"] [unique_id "asjsP0_l3BjACl-QAcrQ1gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 10:41:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 06:40:59.847249 2026] [security2:error] [pid 18535:tid 18535] [client 141.101.98.140:10131] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aroilcontrolsystem.com"] [uri "/.git/config"] [unique_id "asjEu5Y3NudUhoKvnw-0UwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 09:25:17
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 05:25:10.591396 2026] [security2:error] [pid 9147:tid 9147] [client 141.101.98.140:11326] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||cynthiabaxter.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cynthiabaxter.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asiy9v_f2QlNmoFYLf--MgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-08 21:59:15
(2 days ago)
Auto-ban: >3000 req/min op 2026-10-08
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 18:22:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:22:39.029968 2026] [security2:error] [pid 10014:tid 10014] [client 141.101.98.140:12925] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "interforce.com"] [uri "/.htaccess"] [unique_id "asffb7XBmtA7_nXs2PYq9wAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 10:44:21
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 06:44:14.814869 2026] [security2:error] [pid 23310:tid 23310] [client 141.101.98.140:11096] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mdivietnam.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mdivietnam.com"] [uri "/index.php.bak"] [unique_id "asdz_tmZcL4Tm5f5jieXqgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 10:09:00
(2 days ago)
[08/Oct/2026:13:09:00 +0300] -- 141.101.98.140 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[08/Oct/2026:13:09:00 +0300] -- 141.101.98.140 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.dev HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-08 08:09:20
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:10:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:09:54.289343 2026] [security2:error] [pid 23546:tid 23546] [client 141.101.98.140:10941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reciprodyne.com"] [uri "/.env.staging"] [unique_id "asczsjQSUQ4e12U5Yv23AwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-08 05:16:24
(2 days ago)
3 attacks on password/key grabbing URLs:
GET /.ssh/id_rsa HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 04:47:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:47:24.629047 2026] [security2:error] [pid 19924:tid 19924] [client 141.101.98.140:9874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toxicwater.com"] [uri "/.env.staging"] [unique_id "ascgXP-46qW1nl_czhq2wgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:20:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:19:31.493010 2026] [security2:error] [pid 23195:tid 23195] [client 141.101.98.140:10675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rocketcityhotwheelers.com"] [uri "/.svn/entries"] [unique_id "asbvoxPxZgrFfPimeY9ByAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:56:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:56:23.391440 2026] [security2:error] [pid 6302:tid 6302] [client 141.101.98.140:9415] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crescentcitycafe.org"] [uri "/.svn/entries"] [unique_id "asbcJ4gf0mbXIcluDX1u6gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack