π©πͺ
altenglaner
2026-10-09 14:51:06
(6 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 10:46:50
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 06:46:46.541729 2026] [security2:error] [pid 14898:tid 14898] [client 141.101.98.152:13144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmexico.co"] [uri "/.env.dev"] [unique_id "asjGFrWHPFq2DpysN4WOowAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 09:13:12
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 05:13:03.855347 2026] [security2:error] [pid 20007:tid 20007] [client 141.101.98.152:12692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tcmu.org"] [uri "/.env.local"] [unique_id "asiwH1YZsPHdT7g6U6uR1gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 22:52:50
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:52:42.696911 2026] [security2:error] [pid 8548:tid 8548] [client 141.101.98.152:11772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zebax.com"] [uri "/.env.bak"] [unique_id "asgeutFYVYMPN36f-P7p0wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 15:59:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 11:58:57.126186 2026] [security2:error] [pid 5992:tid 5992] [client 141.101.98.152:9972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ironpagoda.com"] [uri "/wp-config.php"] [unique_id "ase9wXQMBomja0WdDQj3-AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
louis77
2026-10-08 13:34:41
(1 day ago)
PHP application attack attempt - Path: /index copy.php, Method: GET, UA: Mozilla/5.0 (iPhone; CPU iP ...
show more
PHP application attack attempt - Path: /index copy.php, Method: GET, UA: Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1
show less
Web App Attack
π§π·
dominioz
2026-10-08 04:44:47
(1 day ago)
2026-10-08 04:39:37 GET /.env.bak - - 141.101.98.152 HTTP/2 Mozilla/5.0+(iPhone;+CPU+iPhone+OS+17_3_ ...
show more
2026-10-08 04:39:37 GET /.env.bak - - 141.101.98.152 HTTP/2 Mozilla/5.0+(iPhone;+CPU+iPhone+OS+17_3_1+like+Mac+OS+X)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.3+Mobile/15E148+Safari/604.1 - 404 0
2026-10-08 04:44:27 GET /.git-credentials - - 141.101.98.152 HTTP/2 Mozilla/5.0+(iPhone;+CPU+iPhone+OS+17_3_1+like+Mac+OS+X)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.3+Mobile/15E148+Safari/604.1 - 404 0
2026-10-08 04:44:28 GET /.kube/config - - 141.101.98.152 HTTP/2 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/122.0.0.0+Safari/537.36+Edg/122.0.0.0 - 404 0
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 02:12:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 22:12:16.041190 2026] [security2:error] [pid 32757:tid 32757] [client 141.101.98.152:12305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arkml.com"] [uri "/wp-config.php"] [unique_id "asb8AD0tsI2abldRAJUhDgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
altenglaner
2026-10-08 01:03:35
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 00:34:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:34:18.420406 2026] [security2:error] [pid 29968:tid 29968] [client 141.101.98.152:13022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jfexpressfr8.com"] [uri "/.env.dev"] [unique_id "asblCu3HHuzcCL--_DrbMwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 00:25:37
(1 day ago)
141.101.98.152 - - [08/Oct/2026:02:25:36 +0200] "GET /. HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows ...
show more
141.101.98.152 - - [08/Oct/2026:02:25:36 +0200] "GET /. HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
show less
Web App Attack
πΈπͺ
Esko
2026-10-07 23:17:28
(1 day ago)
141.101.98.152 - - [07/Oct/2026:23:17:28 +0000] "GET /wp-config.php.old HTTP/1.1" 488 0 "-" "Mozilla ...
show more
141.101.98.152 - - [07/Oct/2026:23:17:28 +0000] "GET /wp-config.php.old HTTP/1.1" 488 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 22:13:38
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:13:33.500173 2026] [security2:error] [pid 18034:tid 18034] [client 141.101.98.152:11976] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fixitsmart.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fixitsmart.com"] [uri "/index.php.bak"] [unique_id "asbEDXC7qUz6of2Ye8Uc3gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-10-07 21:59:27
(1 day ago)
Auto-ban: >3000 req/min op 2026-10-07
Web App Attack
SSH
Hacking
π³π±
Alt255
2026-10-07 21:31:07
(2 days ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.98.152 - - [07/Oct/2026:23:31:07 +0200] "GET /.env.old HTTP/1.1" 301 583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
...
show less
Bad Web Bot
Web App Attack