π©πͺ
altenglaner
2026-10-10 16:44:57
(1 hour ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 13:41:36
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 09:41:26.147015 2026] [security2:error] [pid 2280:tid 2280] [client 141.101.98.227:12022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ourdailybroad.com"] [uri "/.env.staging"] [unique_id "aspAhmSQfgZ6rd5HDPSjnAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 12:52:43
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 08:52:36.841449 2026] [security2:error] [pid 14698:tid 14698] [client 141.101.98.227:9345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peradotto.net"] [uri "/.htaccess"] [unique_id "aso1FMNjzxmurUiY6jJ0vwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-10 07:56:12
(9 hours ago)
[10/Oct/2026:10:56:12 +0300] -- 141.101.98.227 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[10/Oct/2026:10:56:12 +0300] -- 141.101.98.227 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.docker/config.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-10-09 13:55:50
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π©πͺ
s@ch@
2026-10-08 22:30:06
(1 day ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-08 10:08:55
(2 days ago)
[08/Oct/2026:13:08:54 +0300] -- 141.101.98.227 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[08/Oct/2026:13:08:54 +0300] -- 141.101.98.227 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-10-08 07:07:05
(2 days ago)
[mx01aln] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.98.227 - - [08/Oct/2026:09:06:58 +0200] "GET /.git/HEAD HTTP/2.0" 301 470 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
141.101.98.227 - - [08/Oct/2026:09:06:58 +0200] "GET /.svn/entries HTTP/2.0" 301 470 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 07:02:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:01:56.882933 2026] [security2:error] [pid 9189:tid 9189] [client 141.101.98.227:9325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whodatnation.com"] [uri "/wp-config.php.save"] [unique_id "asc_5IQIpdE-vnaXHd7W3AAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 06:33:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:33:04.390124 2026] [security2:error] [pid 31236:tid 31236] [client 141.101.98.227:13748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swiss-pac.com"] [uri "/.env"] [unique_id "asc5IHi2fub2YMJw4Mof-wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 05:33:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 01:33:28.953476 2026] [security2:error] [pid 7588:tid 7588] [client 141.101.98.227:13634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelimts.com"] [uri "/.env.production"] [unique_id "ascrKJD3oO6nhA9R55BH-AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 03:54:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:54:45.689404 2026] [security2:error] [pid 2067:tid 2067] [client 141.101.98.227:12021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captechtraining.com"] [uri "/.env.local"] [unique_id "ascUBfmUhvGholoc_lLhOQAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 03:35:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:35:05.328435 2026] [security2:error] [pid 16247:tid 16247] [client 141.101.98.227:10564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "damonmarks.com"] [uri "/.htaccess"] [unique_id "ascPaU1VyUC60BDNOQB8VAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 03:06:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:06:50.154926 2026] [security2:error] [pid 30769:tid 30769] [client 141.101.98.227:12084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nealandmichaeledesign.com"] [uri "/.env.local"] [unique_id "ascIymSmVtoJclZrOyKsdQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-10-08 01:21:35
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack