๐บ๐ธ
TPI-Abuse
2026-09-30 11:22:21
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:22:12.625541 2026] [security2:error] [pid 2370:tid 2370] [client 141.101.98.153:10698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cccorponline.com"] [uri "/.env.backup"] [unique_id "arzw5Fd_Poz2Ku0PInK3ZgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-09-30 09:36:55
(4 hours ago)
Web App Attack Exploid from 141.101.98.153
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:48:18
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:48:12.747458 2026] [security2:error] [pid 6851:tid 6851] [client 141.101.98.153:13434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jasonpolland.com"] [uri "/.git/HEAD"] [unique_id "arwV_Md-1gDOOXoDUuNS2AAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 05:41:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 01:41:20.371217 2026] [security2:error] [pid 26267:tid 26267] [client 141.101.98.153:12799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "exhaustthelimits.org"] [uri "/.git/config"] [unique_id "artPgMxvcn1ZGq6Ivmb_VQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-28 14:24:34
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
Anonymous
2026-09-26 19:45:33
(3 days ago)
"Packet Flood; Triggered WAF; Persistent 404 Attempts"
DDoS Attack
๐ฉ๐ช
Viveronese
2026-09-26 14:45:03
(3 days ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 13:56:47
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 09:56:41.469825 2026] [security2:error] [pid 1024:tid 1024] [client 141.101.98.153:13834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mirandaracewalks.com"] [uri "/.env.backup"] [unique_id "arfPGYOAzTikUAvUv2w-0wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
joharikop
2026-09-26 13:51:17
(4 days ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 10:53:58
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 06:53:53.189941 2026] [security2:error] [pid 9431:tid 9431] [client 141.101.98.153:9668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mikeziegler.com"] [uri "/.env.staging"] [unique_id "arekQSb0T-Z817aT-6gsXQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 10:05:23
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 06:05:19.664548 2026] [security2:error] [pid 19385:tid 19385] [client 141.101.98.153:11462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.localpetsitters.com"] [uri "/wp-config.php"] [unique_id "areY31sN-62djU46RGH-GQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-09-24 12:58:34
(6 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-09-21 06:20:01
(1 week ago)
"Packet Flood; Triggered WAF; Persistent 404 Attempts"
DDoS Attack
๐ง๐ช
madeit
2026-09-14 05:08:53
(2 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 02:58:23
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 22:58:16.605992 2026] [security2:error] [pid 2190173:tid 2190175] [client 141.101.98.153:10560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crosstheatreorg.pwrcoupling.com"] [uri "/.env.dev"] [unique_id "adcVyLDhYdNF5lVMrulf8gAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack