๐ช๐ธ
Gem
2026-10-09 22:08:01
(7 hours ago)
Unauthorized web scan.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:41:27
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:41:19.068029 2026] [security2:error] [pid 7057:tid 7057] [client 141.101.98.143:9481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynosurephotography.com"] [uri "/.git/config"] [unique_id "aslDX-vvQY7kgjRWKUWp5wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 13:33:38
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 09:33:34.651675 2026] [security2:error] [pid 8957:tid 8957] [client 141.101.98.143:9553] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lancemarthaler.com"] [uri "/.env.dev"] [unique_id "asjtLjcV6e3hdEXagRPqpAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-09 09:21:34
(19 hours ago)
[09/Oct/2026:12:21:34 +0300] -- 141.101.98.143 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[09/Oct/2026:12:21:34 +0300] -- 141.101.98.143 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.save HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-09 00:27:55
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
Inartis
2026-10-08 17:13:45
(1 day ago)
141.101.98.143 - - [08/Oct/2026:19:00:27 +0200] "GET /.git/config HTTP/1.1" 403 5223 "-" "Mozilla/5. ...
show more
141.101.98.143 - - [08/Oct/2026:19:00:27 +0200] "GET /.git/config HTTP/1.1" 403 5223 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
141.101.98.143 - - [08/Oct/2026:19:13:39 +0200] "GET /.env.old HTTP/1.1" 403 5531 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
141.101.98.143 - - [08/Oct/2026:19:13:44 +0200] "GET /.env.bak HTTP/1.1" 302 503 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 10:57:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 06:56:54.934230 2026] [security2:error] [pid 1266:tid 1266] [client 141.101.98.143:10397] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.videoverse.com"] [uri "/.env.save"] [unique_id "asd29t1oRPVx7D2uAQHowAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 09:06:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:06:08.810925 2026] [security2:error] [pid 28080:tid 28080] [client 141.101.98.143:13128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brasscadillac.com"] [uri "/.env.dev"] [unique_id "asddAByMlXJSJeqq-S46bwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 08:04:18
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 07:16:55
(1 day ago)
[08/Oct/2026:10:16:54 +0300] -- 141.101.98.143 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[08/Oct/2026:10:16:54 +0300] -- 141.101.98.143 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 06:59:50
(1 day ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.98.143 - - [08/Oct/2026:08:59:27 +0200] "GET /.env.bak HTTP/1.1" 301 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:46:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:46:46.128044 2026] [security2:error] [pid 32245:tid 32245] [client 141.101.98.143:10598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ppichardocigars.com"] [uri "/wp-config.php.old"] [unique_id "ascSJgBL9LGVH8eMDoAiWwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:12:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:12:00.839042 2026] [security2:error] [pid 24127:tid 24127] [client 141.101.98.143:9947] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ohwaitiforgot.com"] [uri "/wp-config.php.save"] [unique_id "ascKAIaKNPrhDPi11qWWlQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:37:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:36:59.985800 2026] [security2:error] [pid 23651:tid 23666] [client 141.101.98.143:10942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arthansl.com"] [uri "/.svn/entries"] [unique_id "asbzuyK6fxp77zH4kaO__gAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 00:53:26
(2 days ago)
Sensitive Configuration File Disclosure.
Hacking