๐บ๐ธ
TPI-Abuse
2026-10-08 11:00:23
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:00:17.626961 2026] [security2:error] [pid 30137:tid 30137] [client 141.101.98.146:9716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnberk.com"] [uri "/.env.dev"] [unique_id "asd3wbFXqvRrAVtFO_x2KQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 10:08:56
(1 hour ago)
[08/Oct/2026:13:08:56 +0300] -- 141.101.98.146 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[08/Oct/2026:13:08:56 +0300] -- 141.101.98.146 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.docker/config.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 09:08:28
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:08:22.656873 2026] [security2:error] [pid 10914:tid 10914] [client 141.101.98.146:12496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brasscadillac.com"] [uri "/.env.bak"] [unique_id "asddhnxB7-JDcysRq0gqbwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:53:13
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:53:03.366554 2026] [security2:error] [pid 29579:tid 29579] [client 141.101.98.146:11461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mainescentsecrets.com"] [uri "/.env.staging"] [unique_id "asdL38D4JNiKMihLitt0VgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:35:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:35:48.697322 2026] [security2:error] [pid 5772:tid 5913] [client 141.101.98.146:10391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vaprivatecollection.com"] [uri "/.env.local"] [unique_id "asc5xDI9fypBil6DD8ReyAAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 05:59:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 01:59:07.092228 2026] [security2:error] [pid 3602:tid 3602] [client 141.101.98.146:14302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.frankweyer.com"] [uri "/.env.staging"] [unique_id "ascxK4QXolL4IWinlc9h3QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 05:38:06
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 01:37:48.845587 2026] [security2:error] [pid 13140:tid 13140] [client 141.101.98.146:13605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelimts.com"] [uri "/.env.local"] [unique_id "ascsLOmstvNfF-1uVbhstQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
bohl-aiG5aef
2026-10-08 02:47:28
(8 hours ago)
Suricata Alert [SID:2009955] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerab ...
show more
Suricata Alert [SID:2009955] ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-08 02:10:35
(9 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:19:15
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:18:27.536976 2026] [security2:error] [pid 10325:tid 10325] [client 141.101.98.146:10446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnlittlehorn.com"] [uri "/wp-config.php"] [unique_id "asbvY_oRzul5xBdhP48cRwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:05:21
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:04:46.243868 2026] [security2:error] [pid 23527:tid 23562] [client 141.101.98.146:10013] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pattinauction.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pattinauction.com"] [uri "/index.php.bak"] [unique_id "asbeHrx94Ypj1U8E1kEl8wAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-07 23:56:30
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 20:05:36
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:05:21.267779 2026] [security2:error] [pid 12227:tid 12227] [client 141.101.98.146:12628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mylesmitchell.com"] [uri "/.env.bak"] [unique_id "asamAf7f0q64-7hsVMidwAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 12:46:20
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:46:14.213092 2026] [security2:error] [pid 25057:tid 25057] [client 141.101.98.146:14021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daisyweddinginvitations.com"] [uri "/.env.backup"] [unique_id "asY_FndzEZh7BASOdfs1GQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-07 09:26:48
(1 day ago)
Multiple WAF Violations
Web App Attack