๐บ๐ธ
TPI-Abuse
2026-10-08 01:45:50
(11 minutes ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:45:43.580874 2026] [security2:error] [pid 25824:tid 25824] [client 141.101.98.217:13180] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cs-mall.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cs-mall.com"] [uri "/index.php.bak"] [unique_id "asb1x1nHCZj-b2JuFRBedgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:27:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:27:37.883058 2026] [security2:error] [pid 15203:tid 15203] [client 141.101.98.217:10488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garon.us"] [uri "/.env.bak"] [unique_id "asbVabCe893xqPhV3nn3cAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-07 22:01:15
(3 hours ago)
Auto-ban: >3000 req/min op 2026-10-07
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Alt255
2026-10-07 21:49:03
(4 hours ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.98.217 - - [07/Oct/2026:23:49:02 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 601 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 21:21:19
(4 hours ago)
[08/Oct/2026:00:21:18 +0300] -- 141.101.98.217 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[08/Oct/2026:00:21:18 +0300] -- 141.101.98.217 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-07 21:14:46
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 09:39:27
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:39:22.041968 2026] [security2:error] [pid 6062:tid 6062] [client 141.101.98.217:12293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.voodooshop.com"] [uri "/wp-config.php.bak"] [unique_id "asYTStLQcDnVds7fSlWeBAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 09:17:26
(16 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 06:38:46
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:38:36.695831 2026] [security2:error] [pid 26700:tid 26700] [client 141.101.98.217:12859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evolutionmedical.help"] [uri "/.env.save"] [unique_id "asXo7DrWbt5GoaGBqmtveQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-07 05:14:13
(20 hours ago)
3 attacks on env grabbing URLs:
GET /.env.save HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-06 22:59:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:59:40.565477 2026] [security2:error] [pid 28648:tid 28648] [client 141.101.98.217:11507] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fancycleaners.com"] [uri "/.env.staging"] [unique_id "asV9XIBVOVBzsl6SdtdhFAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 22:00:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:00:28.907192 2026] [security2:error] [pid 26055:tid 26055] [client 141.101.98.217:14030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "humbliaslaw.com"] [uri "/.env"] [unique_id "asVvfBZklUYSQ9y60cjtwAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:38:46
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:38:37.996106 2026] [security2:error] [pid 9556:tid 9556] [client 141.101.98.217:10999] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||toytractorrepair.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "toytractorrepair.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asUkDZ1JXSqDBHOX82R7dwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:01:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:01:00.867024 2026] [security2:error] [pid 16886:tid 16886] [client 141.101.98.217:11608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rx-art.com"] [uri "/.env"] [unique_id "asTi_Nf2UCRCqz8TZSRmzgAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 08:50:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:50:46.956082 2026] [security2:error] [pid 10948:tid 10948] [client 141.101.98.217:12735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fingercult.com"] [uri "/wp-config.php.save"] [unique_id "asS2Zg5mMONnrHNoizI4mwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack