๐ช๐ธ
bohl-aiG5aef
2026-10-08 14:46:16
(3 hours ago)
Suricata Alert [SID:2019526] ET WEB_SERVER WEB-PHP phpinfo access
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 13:20:09
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:20:02.470127 2026] [security2:error] [pid 1875:tid 1875] [client 141.101.98.142:10343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.havilahmalone.com"] [uri "/.env"] [unique_id "aseYgkJ2Ax5eTWOjWExwOgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 12:24:25
(5 hours ago)
(caddyscan) Scanner path probe from 141.101.98.142 (GB/United Kingdom/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 141.101.98.142 (GB/United Kingdom/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 141.101.98.142 - - [08/Oct/2026:12:24:22 +0000] "GET /.ssh/id_ed25519 HTTP/1.1"
[REDACTED] 200 2627 141.101.98.142 - - [08/Oct/2026:12:24:23 +0000] "GET /.ssh/id_ed25519 HTTP/1.1"
[REDACTED] 200 2627 141.101.98.142 - - [08/Oct/2026:12:24:23 +0000] "GET /.ssh/id_rsa HTTP/1.1"
[REDACTED] 200 2627 141.101.98.142 - - [08/Oct/2026:12:24:23 +0000] "GET /wp-config.php HTTP/1.1"
[REDACTED] 200 2627 141.101.98.142 - - [08/Oct/2026:12:24:25 +0000] "GET /.htaccess HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-08 11:56:06
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:55:57.173742 2026] [security2:error] [pid 14335:tid 14335] [client 141.101.98.142:14301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wsspy.com"] [uri "/.env.save"] [unique_id "aseEzeh81cooo6ZNgA6nogAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 10:57:03
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 06:56:54.934584 2026] [security2:error] [pid 2005:tid 2005] [client 141.101.98.142:11775] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.videoverse.com"] [uri "/.env.production"] [unique_id "asd29oxXgUSx3_Ns13n3DAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
conrad10781
2026-10-08 10:37:58
(7 hours ago)
nginx-dot-env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 09:06:17
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:06:09.616806 2026] [security2:error] [pid 6685:tid 6685] [client 141.101.98.142:9392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brasscadillac.com"] [uri "/.env.dev"] [unique_id "asddAVtAK0MCPn_z-4SSuAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 07:12:12
(11 hours ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.98.142 - - [08/Oct/2026:09:11:51 +0200] "GET /.svn/entries HTTP/1.1" 301 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:54:51
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:54:37.962447 2026] [security2:error] [pid 11366:tid 11393] [client 141.101.98.142:12367] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vaprivatecollection.com"] [uri "/.env.bak"] [unique_id "asc-LfMOUEqCP6oFWMC5qgAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:46:52
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:46:44.476078 2026] [security2:error] [pid 23864:tid 23864] [client 141.101.98.142:13530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ppichardocigars.com"] [uri "/.env.bak"] [unique_id "ascSJGxmvjo-2gcaHHK3QwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:12:08
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:12:00.136901 2026] [security2:error] [pid 21097:tid 21097] [client 141.101.98.142:9572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ohwaitiforgot.com"] [uri "/wp-config.php"] [unique_id "ascKABas-Ox1wVtIyhN3XgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:44:16
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:44:12.433207 2026] [security2:error] [pid 23651:tid 23655] [client 141.101.98.142:13841] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arthansl.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arthansl.com"] [uri "/index.php.bak"] [unique_id "asb1bCK6fxp77zH4kaPARQAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 00:53:25
(17 hours ago)
Web Server Exposed Git Repository Information Disclosure.
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-10-08 00:04:03
(18 hours ago)
[08/Oct/2026:03:04:01 +0300] -- 141.101.98.142 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[08/Oct/2026:03:04:01 +0300] -- 141.101.98.142 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 12:25:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:25:38.305940 2026] [security2:error] [pid 26671:tid 26671] [client 141.101.98.142:9932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mountainjaytherapy.com"] [uri "/.env.backup"] [unique_id "asY6QmgxcvkwkRhErdH3NwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack