π©πͺ
MarkGGN
2026-10-05 02:25:31
(2 hours ago)
Web attack. 141.101.98.37 - - [05/Oct/2026:04:24:26 +0200] "GET /.env.old HTTP/2.0" 200 0 "-" "Mozil ...
show more
Web attack. 141.101.98.37 - - [05/Oct/2026:04:24:26 +0200] "GET /.env.old HTTP/2.0" 200 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
141.101.98.37 - - [05/Oct/2026:04:25:31 +0200] "GET /wp-config.php.bak HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 02:09:56
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 22:09:48.860590 2026] [security2:error] [pid 25679:tid 25679] [client 141.101.98.37:13104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.teleplussolutions.com"] [uri "/.env.local"] [unique_id "ar3A7Cz2J4VtpeqVp35ulwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-09-30 23:33:00
(4 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
π¬π§
blik2108
2026-09-30 19:54:55
(4 days ago)
141.101.98.37 - - [30/Sep/2026:19:54:39 +0000] "GET /.git/config HTTP/1.1" 404 555 "-" "Mozilla/5.0 ...
show more
141.101.98.37 - - [30/Sep/2026:19:54:39 +0000] "GET /.git/config HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0" "2a06:98c0:3600::103"
141.101.98.37 - - [30/Sep/2026:19:54:39 +0000] "GET /.svn/entries HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103"
141.101.98.37 - - [30/Sep/2026:19:54:39 +0000] "GET /.npmrc HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1" "2a06:98c0:3600::103"
141.101.98.37 - - [30/Sep/2026:19:54:45 +0000] "GET /.ssh/id_rsa HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "2a06:98c0:3600::103"
141.101.98.37 - - [30/Sep/2026:19:54:45 +0000] "GET /wp-c
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 14:18:44
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:18:40.091234 2026] [security2:error] [pid 12083:tid 12083] [client 141.101.98.37:12055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stoneageartifacts.com"] [uri "/wp-config.php"] [unique_id "ar0aQNVAH6WXn4rWlSpTdQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 03:21:52
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:21:48.918071 2026] [security2:error] [pid 10543:tid 10543] [client 141.101.98.37:11010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ismaelcavazos.com"] [uri "/.env.staging"] [unique_id "aryATKtUO7DakIQNLZ1l8wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 00:47:03
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:46:57.860280 2026] [security2:error] [pid 8137:tid 8137] [client 141.101.98.37:11463] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "braunfamily.info"] [uri "/.env.backup"] [unique_id "arxcAXD5wwVz_lAXvBZFewAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 00:07:11
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:07:07.939536 2026] [security2:error] [pid 2444:tid 2469] [client 141.101.98.37:10815] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.managementconsultantcertification.com"] [uri "/.git/HEAD"] [unique_id "arxSq_VQTnmflSwlQ5c9AQAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 13:43:06
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:43:01.819175 2026] [security2:error] [pid 28245:tid 29081] [client 141.101.98.37:10916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clearwaterpumpservices.com"] [uri "/.env.staging"] [unique_id "arvAZRf_Ga-blh2-ybTnjQAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 23:33:21
(6 days ago)
apache vulnerability scan
Web App Attack
πΊπΈ
Lee Daniel
2026-09-28 11:27:13
(6 days ago)
141.101.98.37 - - [28/Sep/2026:07:27:13 -0400] "GET /.htaccess HTTP/1.1" 403 377 "-" "Mozilla/5.0 (W ...
show more
141.101.98.37 - - [28/Sep/2026:07:27:13 -0400] "GET /.htaccess HTTP/1.1" 403 377 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 10:20:56
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 06:20:47.547858 2026] [security2:error] [pid 30682:tid 30682] [client 141.101.98.37:13945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pennylanefarmsauces.com"] [uri "/.env"] [unique_id "aro_f8kV0dj2_eRlntU6KAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-26 23:37:09
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-26 13:13:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 09:13:11.881952 2026] [security2:error] [pid 7360:tid 7360] [client 141.101.98.37:11857] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whiterhinomusic.net"] [uri "/.env"] [unique_id "arfE5_mZYkQe1ExtzxSJOgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-26 12:49:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 08:49:22.005089 2026] [security2:error] [pid 1965:tid 1965] [client 141.101.98.37:9754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mindforestmovie.com"] [uri "/.svn/entries"] [unique_id "are_UgXUY8C8U1IClxNfogAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack