π¬π§
consul.to
2026-10-09 00:45:55
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
homeshowdomain.nl
2026-10-08 21:59:15
(4 hours ago)
Auto-ban: >3000 req/min op 2026-10-08
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-10-08 17:41:39
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:41:33.141008 2026] [security2:error] [pid 2229:tid 2229] [client 141.101.98.157:11566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solcargomiami.com"] [uri "/wp-config.php.bak"] [unique_id "asfVzel02ITQqyF8vY96twAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 06:26:37
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:26:21.074473 2026] [security2:error] [pid 3842:tid 3909] [client 141.101.98.157:13514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.southtampaprinting.com"] [uri "/.env.backup"] [unique_id "asc3jRKyCej0NOQjG7mIvgAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 04:21:37
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:21:07.174573 2026] [security2:error] [pid 6282:tid 6282] [client 141.101.98.157:14033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dunnretired.com"] [uri "/.env.bak"] [unique_id "ascaM2ioAhMG6sAYJ29iPwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 03:23:42
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:23:35.719402 2026] [security2:error] [pid 10844:tid 10844] [client 141.101.98.157:11344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ironsightsarmory.com"] [uri "/.env.backup"] [unique_id "ascMt3xfrEKCtwkWfX2d7gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 00:53:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:52:58.183646 2026] [security2:error] [pid 15744:tid 15744] [client 141.101.98.157:13515] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jfexpressfr8.com"] [uri "/wp-config.php"] [unique_id "asbpajtznCmf-j0Q_2DdqQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 22:03:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:03:30.019483 2026] [security2:error] [pid 5832:tid 5832] [client 141.101.98.157:10690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "televisonic.com"] [uri "/wp-config.php.bak"] [unique_id "asbBslWG4XzdNrQBqwddGQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
DRI
2026-10-07 21:37:36
(1 day ago)
Web attack/Malicious activity detected
Web App Attack
π³π±
Alt255
2026-10-07 21:31:08
(1 day ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.98.157 - - [07/Oct/2026:23:31:07 +0200] "GET /.env.staging HTTP/1.1" 301 591 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 21:20:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:20:28.887290 2026] [security2:error] [pid 32635:tid 32635] [client 141.101.98.157:12972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swhowell.com"] [uri "/.env.old"] [unique_id "asa3nOL8aZRUYMFWH1kfIAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
neckaralb-admin.de
2026-10-07 10:46:50
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
altenglaner
2026-10-07 09:22:11
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-07 07:57:14
(1 day ago)
[07/Oct/2026:10:57:13 +0300] -- 141.101.98.157 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[07/Oct/2026:10:57:13 +0300] -- 141.101.98.157 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /index.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 06:59:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:59:05.172265 2026] [security2:error] [pid 13127:tid 13127] [client 141.101.98.157:9580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdromline.com"] [uri "/.svn/entries"] [unique_id "asXtuVGFBlzXaRJSsQ2RkAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack