๐บ๐ธ
TPI-Abuse
2026-10-08 12:03:26
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 08:03:12.375620 2026] [security2:error] [pid 19272:tid 19272] [client 141.101.98.163:10804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "enriquejezik.com"] [uri "/.env.local"] [unique_id "aseGgLH4TUgeYRlgzfxA4wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 11:12:06
(5 hours ago)
[08/Oct/2026:14:12:05 +0300] -- 141.101.98.163 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[08/Oct/2026:14:12:05 +0300] -- 141.101.98.163 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-08 05:15:35
(11 hours ago)
2 attacks on password/key grabbing URLs:
GET /.git-credentials HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 04:50:12
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:50:03.280588 2026] [security2:error] [pid 19924:tid 19924] [client 141.101.98.163:10403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toxicwater.com"] [uri "/.svn/entries"] [unique_id "ascg-_-46qW1nl_czhq2ywAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:20:37
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:20:23.010467 2026] [security2:error] [pid 24005:tid 24005] [client 141.101.98.163:10201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hatsizes.com"] [uri "/.git/config"] [unique_id "ascaBz7Bl5ngRL6gKYfQngAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-08 04:19:15
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:26:38
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:26:30.624766 2026] [security2:error] [pid 1447:tid 1447] [client 141.101.98.163:11119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "worldofeconomics.com"] [uri "/.env.staging"] [unique_id "asbjNmTu4P69sL-I9BFdMgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-10-08 00:13:53
(16 hours ago)
Suricata: Alert - ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:57:02
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:56:50.258838 2026] [security2:error] [pid 11132:tid 11132] [client 141.101.98.163:9638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "almudenastrust.com"] [uri "/.env.staging"] [unique_id "asbcQj_U-hIatx5CT1ateQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-10-07 21:26:02
(19 hours ago)
141.101.98.163 - - [07/Oct/2026:23:26:02 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ...
show more
141.101.98.163 - - [07/Oct/2026:23:26:02 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
p0tatosmash3r
2026-10-07 18:16:01
(22 hours ago)
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration ...
show more
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration.
show less
Web App Attack
Bad Web Bot
๐ช๐ธ
robotstxt
2026-10-07 17:14:18
(23 hours ago)
141.101.98.163 - - [07/Oct/2026:17:13:23 +0000] "GET /.svn/entries HTTP/2.0" 403 0 "-" "Mozilla/5.0 ...
show more
141.101.98.163 - - [07/Oct/2026:17:13:23 +0000] "GET /.svn/entries HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1" "2a06:98c0:3600::103" edge="141.101.98.163"
141.101.98.163 - - [07/Oct/2026:17:13:24 +0000] "GET /.npmrc HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="141.101.98.163"
141.101.98.163 - - [07/Oct/2026:17:13:24 +0000] "GET /.docker/config.json HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="141.101.98.163"
141.101.98.163 - - [07/Oct/2026:17:13:24 +0000] "GET /.npmrc HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="141.101.98.163"
...
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-10-07 09:51:14
(1 day ago)
141.101.98.163 - - [07/Oct/2026:09:50:11 +0000] "GET /.kube/config HTTP/2.0" 403 0 "-" "Mozilla/5.0 ...
show more
141.101.98.163 - - [07/Oct/2026:09:50:11 +0000] "GET /.kube/config HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103" edge="141.101.98.163"
141.101.98.163 - - [07/Oct/2026:09:50:12 +0000] "GET /wp-config.php HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15" "2a06:98c0:3600::103" edge="141.101.98.163"
141.101.98.163 - - [07/Oct/2026:09:50:12 +0000] "GET /config.php HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0" "2a06:98c0:3600::103" edge="141.101.98.163"
141.101.98.163 - - [07/Oct/2026:09:50:12 +0000] "GET /config.yaml HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1" "2a06:98c0:3600::103" edge="141.101.98.163"
141.101.98.163
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 04:28:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:27:59.572911 2026] [security2:error] [pid 25777:tid 25777] [client 141.101.98.163:9391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blacksheepoffroad.com"] [uri "/.htaccess"] [unique_id "asXKTyuUs1Kv1VguUsu4QwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 02:27:14
(1 day ago)
[07/Oct/2026:05:27:13 +0300] -- 141.101.98.163 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[07/Oct/2026:05:27:13 +0300] -- 141.101.98.163 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php.old HTTP/1.1
show less
Bad Web Bot
Web App Attack