๐ช๐ธ
bohl-aiG5aef
2026-10-11 01:16:44
(2 hours ago)
Suricata Alert [SID:2031502] ET INFO Request to Hidden Environment File - Inbound
Hacking
๐ฏ๐ต
VXG-NET
2026-10-10 20:18:44
(7 hours ago)
port=80, indicator_type=info-leak
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-10 15:44:47
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 11:44:42.404773 2026] [security2:error] [pid 19265:tid 19265] [client 141.101.98.173:11665] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pasadenahairextensions.com"] [uri "/.svn/entries"] [unique_id "aspdalkvzts2YyunxbuiCgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 10:35:10
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 06:34:52.402488 2026] [security2:error] [pid 17827:tid 17827] [client 141.101.98.173:10352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pourier.net"] [uri "/.env.local"] [unique_id "asoUzEqHY6_2johdfNpx-gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-10 01:42:35
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 22:52:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 18:52:48.842625 2026] [security2:error] [pid 17686:tid 17686] [client 141.101.98.173:14165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "islandsuperbook.net"] [uri "/.git/HEAD"] [unique_id "aslwQFJIWd0r5-VTOsTW0QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-09 19:17:34
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-09 14:07:16
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ง๐ท
dominioz
2026-10-09 10:33:47
(1 day ago)
2026-10-09 10:33:35 GET /.env.local - - 141.101.98.173 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64; ...
show more
2026-10-09 10:33:35 GET /.env.local - - 141.101.98.173 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/122.0.0.0+Safari/537.36 - 404 0
2026-10-09 10:33:36 GET /.env.staging - - 141.101.98.173 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/122.0.0.0+Safari/537.36 - 404 0
2026-10-09 10:33:36 GET /.docker/config.json - - 141.101.98.173 HTTP/1.1 Mozilla/5.0+(iPhone;+CPU+iPhone+OS+17_3_1+like+Mac+OS+X)+AppleWebKit/605.1.15+(KHTML,+like+Gecko)+Version/17.3+Mobile/15E148+Safari/604.1 - 403 0
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 06:38:18
(1 day ago)
141.101.98.173 - - [09/Oct/2026:06:38:16 +0000] "GET /.env.staging HTTP/1.1" 302 645 "-" "Mozilla/5. ...
show more
141.101.98.173 - - [09/Oct/2026:06:38:16 +0000] "GET /.env.staging HTTP/1.1" 302 645 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:14:54
(1 day ago)
3 attacks on password/key grabbing URLs:
GET /.aws/credentials HTTP/1.1
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-10-09 04:49:42
(1 day ago)
[09/Oct/2026:07:49:41 +0300] -- 141.101.98.173 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[09/Oct/2026:07:49:41 +0300] -- 141.101.98.173 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.dev HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 04:09:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:09:15.433382 2026] [security2:error] [pid 19532:tid 19540] [client 141.101.98.173:9789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beelineproductions.com"] [uri "/.env.backup"] [unique_id "asho61qhOYsUemBtzuE0BwAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 15:10:55
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 12:56:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 08:56:27.253041 2026] [security2:error] [pid 14147:tid 14147] [client 141.101.98.173:12643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peaksalesnw.com"] [uri "/.env.dev"] [unique_id "aseS-_VgJCeJTFTRjBI49AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack