๐บ๐ธ
TPI-Abuse
2026-10-06 16:11:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:10:32.721245 2026] [security2:error] [pid 7448:tid 7448] [client 141.101.98.191:12559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chezlubacov.org"] [uri "/.env"] [unique_id "asUdeMB171u1xeX3ruZvVwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-06 15:10:21
(3 hours ago)
[Wed Oct 07 02:10:18.639634 2026] [security2:error] [pid 261885] [client 141.101.98.191:12473] [clie ...
show more
[Wed Oct 07 02:10:18.639634 2026] [security2:error] [pid 261885] [client 141.101.98.191:12473] [client 141.101.98.191] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/%2f%2eaws%2fcredentials"] [unique_id "asUPWpw6kwy1vwtiV9uXKAAAAAg"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:25:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:25:11.315660 2026] [security2:error] [pid 25967:tid 25967] [client 141.101.98.191:11162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrflatpeople.com"] [uri "/.htaccess"] [unique_id "asTop2WwN493HwRqm4KQxQAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:08:26
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:08:20.352421 2026] [security2:error] [pid 4690:tid 4690] [client 141.101.98.191:11995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zodiacwin.com"] [uri "/.env.dev"] [unique_id "asTktLNOHVnB0UeCjDF2iwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:42:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:42:06.564473 2026] [security2:error] [pid 7691:tid 7691] [client 141.101.98.191:10981] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "contrarianadvisors.com"] [uri "/wp-config.php.save"] [unique_id "asTQftfvr3TwygbTvX11GQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:50:58
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:50:46.622101 2026] [security2:error] [pid 10803:tid 10803] [client 141.101.98.191:11926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "getitenglish.com"] [uri "/.env.production"] [unique_id "asTEdooglxHJxm5VtnQOUQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 02:09:09
(16 hours ago)
Bot detected scanning for vulnerable pages
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-05 22:46:06
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:46:02.368291 2026] [security2:error] [pid 32647:tid 32647] [client 141.101.98.191:12030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "landjudging.com"] [uri "/.env.backup"] [unique_id "asQoqp_3MtKlgEJwDnxYhAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-05 22:26:57
(19 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-10-04 02:38:21
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-02 21:44:11
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, path_traversal. Observed by 1 sensor(s); 11 hits.
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-02 18:25:10
(3 days ago)
[02/Oct/2026:21:25:09 +0300] -- 141.101.98.191 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[02/Oct/2026:21:25:09 +0300] -- 141.101.98.191 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /app/.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:06:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:06:29.231939 2026] [security2:error] [pid 14403:tid 14403] [client 141.101.98.191:9324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bizzybeejunkremoval.com"] [uri "/.svn/entries"] [unique_id "ar6FBdUuD9FF6Nk_DV2HowAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:49:27
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:49:18.855668 2026] [security2:error] [pid 14121:tid 14121] [client 141.101.98.191:9569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1214productions.com"] [uri "/.env"] [unique_id "ar5Ivt26woheiOXxUlbiEgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 05:05:32
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:05:28.761547 2026] [security2:error] [pid 8284:tid 8284] [client 141.101.98.191:9424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hope4elsalvador.org"] [uri "/.env.production"] [unique_id "ar3qGLAunBC4m5Kgg871EAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack