๐บ๐ธ
TPI-Abuse
2026-10-07 09:06:21
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:05:48.074249 2026] [security2:error] [pid 5505:tid 5505] [client 141.101.98.15:13045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rodzillacharters.com"] [uri "/wp-config.php.bak"] [unique_id "asYLbN54LMCzEAZwa6c6fAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 00:35:39
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 20:35:31.889420 2026] [security2:error] [pid 3005:tid 3005] [client 141.101.98.15:13897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jsommer.com"] [uri "/wp-config.php.old"] [unique_id "asWT03RpfPwbzKVqNfNlYwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:53:31
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:53:01.143920 2026] [security2:error] [pid 14881:tid 14881] [client 141.101.98.15:14134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-malta.com"] [uri "/.env.save"] [unique_id "asWJ3TURloeptrFth0OHUwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:35:15
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:34:58.452210 2026] [security2:error] [pid 27040:tid 27040] [client 141.101.98.15:9323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arnoldwell.com"] [uri "/wp-config.php"] [unique_id "asUjMr_go9Ls52qr9P6kQgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:53:01
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:52:56.192209 2026] [security2:error] [pid 10218:tid 10218] [client 141.101.98.15:11568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehomemailbox.com"] [uri "/.svn/entries"] [unique_id "asULSOpXvbZnwOqjoxGiegAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:12:41
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:12:34.313064 2026] [security2:error] [pid 22093:tid 22093] [client 141.101.98.15:10784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "herstonfarm.com"] [uri "/.env.bak"] [unique_id "asUB0swqRIhmdz-WbFc1xwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-06 12:46:45
(22 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ฉ๐ช
4server
2026-10-06 12:14:20
(22 hours ago)
[TueOct0614:14:13.4010402026][security2:error][pid3654295:tid3654388][client141.101.98.15:0]ModSecur ...
show more
[TueOct0614:14:13.4010402026][security2:error][pid3654295:tid3654388][client141.101.98.15:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"hosting-royal.ch\"][uri\"/.git/config\"][unique_id\"asTmFbFK35gzGTm5HKH2qgAAAcc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:58:36
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:58:15.067933 2026] [security2:error] [pid 29955:tid 29955] [client 141.101.98.15:12291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabbathschoolguide.com"] [uri "/.git/HEAD"] [unique_id "asTiV1QRlILAMFYNNUSsfwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-06 11:28:43
(23 hours ago)
[TueOct0613:28:35.7910632026][security2:error][pid2283022:tid2283028][client141.101.98.15:0]ModSecur ...
show more
[TueOct0613:28:35.7910632026][security2:error][pid2283022:tid2283028][client141.101.98.15:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"hostingsvizzera.ch\"][uri\"/wp-config.php.save\"][unique_id\"asTbYxvCowJjTE05LY9zDAAAAQQ\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:13:08
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:12:57.788754 2026] [security2:error] [pid 26517:tid 26517] [client 141.101.98.15:9651] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||honeybeeplace.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "honeybeeplace.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asTXubiTieFHn4I1luKyzAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-10-06 10:59:23
(23 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: \.ssh/ (Match: .ssh/)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:17:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:17:18.857100 2026] [security2:error] [pid 24387:tid 24387] [client 141.101.98.15:13616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desertalfas.org"] [uri "/wp-config.php"] [unique_id "asTKruseTZJEz3lB_ccs1wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 03:03:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 23:03:12.572604 2026] [security2:error] [pid 27341:tid 27341] [client 141.101.98.15:11881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sparemediagroup.com"] [uri "/.env.local"] [unique_id "asRk8LXNG7rK1wZfwAiv0wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 21:48:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.15 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:48:00.903427 2026] [security2:error] [pid 893673:tid 893678] [client 141.101.98.15:9689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "isoceansl.com"] [uri "/.env"] [unique_id "asQbEGZBYIIkK9OfjrIniQAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack