๐ฉ๐ช
FeG Deutschland
2026-10-03 19:18:13
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-10-02 19:10:36
(2 days ago)
CMS/framework probe: 141.101.98.156 - - [02/Oct/2026:21:10:35 +0200] "GET /.aws/credentials HTTP/2.0 ...
show more
CMS/framework probe: 141.101.98.156 - - [02/Oct/2026:21:10:35 +0200] "GET /.aws/credentials HTTP/2.0" 404 94431 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" asn=13335 org="Cloudflare, Inc." country=GB
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-01 16:57:44
(3 days ago)
[01/Oct/2026:19:57:44 +0300] -- 141.101.98.156 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[01/Oct/2026:19:57:44 +0300] -- 141.101.98.156 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-09-30 19:18:44
(4 days ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-30 18:38:34
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-30 16:22:14
(4 days ago)
[30/Sep/2026:19:22:14 +0300] -- 141.101.98.156 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[30/Sep/2026:19:22:14 +0300] -- 141.101.98.156 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:13:06
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:13:00.382106 2026] [security2:error] [pid 8878:tid 8878] [client 141.101.98.156:12119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rldcompany.com"] [uri "/.svn/entries"] [unique_id "arz8zPaps7PAtDQvk01R0gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
debaba
2026-09-30 00:54:42
(5 days ago)
aktiv
[30/Sep/2026:00:54:26.068275 +0000] arxdweoi_ccUvqI1bbIbjgAAAFc 141.101.98.156 43400 127.0.0.1 ...
show more
aktiv
[30/Sep/2026:00:54:26.068275 +0000] arxdweoi_ccUvqI1bbIbjgAAAFc 141.101.98.156 43400 127.0.0.1 7081
[30/Sep/2026:00:54:34.187212 +0000] arxdyeoi_ccUvq
...
show less
Brute-Force
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-30 00:29:41
(5 days ago)
[Wed Sep 30 10:29:40.318429 2026] [security2:error] [pid 302469] [client 141.101.98.156:13515] [clie ...
show more
[Wed Sep 30 10:29:40.318429 2026] [security2:error] [pid 302469] [client 141.101.98.156:13515] [client 141.101.98.156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mareeshefford.com"] [uri "/.git/HEAD"] [unique_id "arxX9PgGZlRmnjYRstXnoQAAAAI"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 12:12:33
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:12:28.565784 2026] [security2:error] [pid 23846:tid 23846] [client 141.101.98.156:11079] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.acatucson.com"] [uri "/.svn/entries"] [unique_id "arurLHd-r7pPEVxhhoCq8gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 10:37:04
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:36:58.502906 2026] [security2:error] [pid 5093:tid 5093] [client 141.101.98.156:14271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stoneybluff.com"] [uri "/.env.production"] [unique_id "aruUyspbI2TU7pxDguW7UQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 06:31:05
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 02:30:57.427064 2026] [security2:error] [pid 25107:tid 25107] [client 141.101.98.156:12085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "al-hafeeztrust.net"] [uri "/.env.staging"] [unique_id "artbISQMd5mhAQEjP_pYRAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-09-29 01:44:23
(6 days ago)
[29/Sep/2026:03:44:12.312596 +0200] arsX7MMbRd5WNZrQ1853tAAAAAY 141.101.98.156 37618 127.0.0.1 7081
...
show more
[29/Sep/2026:03:44:12.312596 +0200] arsX7MMbRd5WNZrQ1853tAAAAAY 141.101.98.156 37618 127.0.0.1 7081
[29/Sep/2026:03:44:12.314537 +0200] arsX7DkX7TpT-MBM3DN85wAAAAM 141.101.98.156 37628 127.0.0.1 7081
[29/Sep/2026:03:44:20.095372 +0200] arsX9MMbRd5WNZrQ1853tQAAAAY 141.101.98.156 48338 127.0.0.1 7081
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-28 08:02:51
(6 days ago)
[28/Sep/2026:11:02:51 +0300] -- 141.101.98.156 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[28/Sep/2026:11:02:51 +0300] -- 141.101.98.156 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 07:38:52
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.156 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.156 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 03:38:43.177931 2026] [security2:error] [pid 1990:tid 1990] [client 141.101.98.156:10969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.franklincountyquilters.org"] [uri "/.env.local"] [unique_id "aroZgxnD0dWo8tuhJ2mBngAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack