π§πͺ
madeit
2026-08-21 15:20:20
(1 week ago)
Web App Attack
π·πΊ
DZBOT
2026-08-04 04:27:06
(4 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-07-17 17:32:44
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
π³π±
COMPLEX
2026-06-05 01:51:53
(2 months ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
π¬π§
sandra361
2026-05-28 07:13:02
(3 months ago)
Port scan detected: 19 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC ...
show more
Port scan detected: 19 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC=141.101.98.194 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=20639 DF PROTO=TCP SPT=61497 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
π©πͺ
acadeova
2026-04-26 13:23:23
(4 months ago)
π¨ Recon detected (nft drop)
SRC=141.101.98.194
Observed=TCP dpt=80 in=enp0s6 ttl=58
Time=recent(jour ...
show more
π¨ Recon detected (nft drop)
SRC=141.101.98.194
Observed=TCP dpt=80 in=enp0s6 ttl=58
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-04-09 04:41:53
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 00:41:47.913275 2026] [security2:error] [pid 192044:tid 192044] [client 141.101.98.194:12820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.glencottagemusic.com"] [uri "/.env.old"] [unique_id "adcuCw0GV9z-wYINdA4ecwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 23:00:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 19:00:24.516915 2026] [security2:error] [pid 2807273:tid 2807273] [client 141.101.98.194:9989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yournewphotos.tijuanabible.org"] [uri "/.env.test"] [unique_id "adbeCO1ieVRgHqAG5rDn0AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 21:12:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 17:12:34.636508 2026] [security2:error] [pid 3106145:tid 3106145] [client 141.101.98.194:10438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.sieder.com"] [uri "/.env.example"] [unique_id "adbEwuV5kDGE6kDQSb6ySQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 20:04:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 16:04:15.539387 2026] [security2:error] [pid 2987478:tid 2987519] [client 141.101.98.194:10305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imasola.com"] [uri "/api/.env"] [unique_id "ada0v9sn3QmU7eqH2tyeHAAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 17:05:20
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 13:05:13.784053 2026] [security2:error] [pid 2503172:tid 2503172] [client 141.101.98.194:10381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.amazedbyu.com"] [uri "/.envrc"] [unique_id "adaKyVJ60l50gxM7H7FyZwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 14:17:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 10:17:26.716606 2026] [security2:error] [pid 2791906:tid 2791906] [client 141.101.98.194:10138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "health-gateways.com"] [uri "/.git/logs/HEAD"] [unique_id "adZjdiSv2Yul0g93_6adXAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 13:59:45
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 09:59:25.197842 2026] [security2:error] [pid 2450024:tid 2450024] [client 141.101.98.194:10187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ferienwohnungen-eva.at"] [uri "/config/.env"] [unique_id "adZfPcRqTNg4AsnUQgzNZAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 12:05:00
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 08:04:55.276876 2026] [security2:error] [pid 2508047:tid 2508047] [client 141.101.98.194:12985] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stagging.omintara.com"] [uri "/config/.env"] [unique_id "adZEZ3tWNUs7A501Hbs1jwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 11:47:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 07:47:21.092185 2026] [security2:error] [pid 2116559:tid 2116559] [client 141.101.98.194:13380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.frenchla.com"] [uri "/.env_config"] [unique_id "adZASVvlda0zgVUxitY6LgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack