πΊπΈ
TPI-Abuse
2026-10-07 03:21:29
(1 minute ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:21:23.125190 2026] [security2:error] [pid 25119:tid 25119] [client 141.101.98.47:13787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3n1ent.com"] [uri "/wp-config.php.save"] [unique_id "asW6s-RalqVrO-RKugendgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 16:21:30
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:21:26.591221 2026] [security2:error] [pid 24209:tid 24209] [client 141.101.98.47:13691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chezlubacov.org"] [uri "/.env.save"] [unique_id "asUgBsH8O_3c6c2rsi0GOQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
paulshipley.com.au
2026-10-06 15:24:47
(11 hours ago)
[Wed Oct 07 02:24:46.661896 2026] [security2:error] [pid 265777] [client 141.101.98.47:12333] [clien ...
show more
[Wed Oct 07 02:24:46.661896 2026] [security2:error] [pid 265777] [client 141.101.98.47:12333] [client 141.101.98.47] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/.svn/entries"] [unique_id "asUSvtqVyLFyhzB0udq1ygAAAAg"]
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 12:26:33
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:26:28.507376 2026] [security2:error] [pid 14611:tid 14611] [client 141.101.98.47:10293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sigiweb.net"] [uri "/.env.bak"] [unique_id "asTo9MqIoxzp-Sm5ru-3bgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 10:44:59
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:44:55.327225 2026] [security2:error] [pid 31216:tid 31299] [client 141.101.98.47:12427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dulemba.com"] [uri "/.env.production"] [unique_id "asTRJ2YK1RaQMxz2DrVT5gAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
altenglaner
2026-10-05 22:26:55
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 21:49:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:49:24.072504 2026] [security2:error] [pid 3764:tid 3764] [client 141.101.98.47:12750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saramics.net"] [uri "/.env.backup"] [unique_id "asQbZL1O5n83fRv6JQ5MPQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 21:17:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:17:36.999902 2026] [security2:error] [pid 31487:tid 31487] [client 141.101.98.47:9309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brbcash.com"] [uri "/.env.save"] [unique_id "asQT8G5Q76_uHu-_n7uE8QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 09:40:08
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-10-05 08:16:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 04:16:06.252809 2026] [security2:error] [pid 15321:tid 15321] [client 141.101.98.47:13193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "insua.com"] [uri "/.env.bak"] [unique_id "asNcxqul198UU6r_yV_vlQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-04 04:11:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 00:11:41.066037 2026] [security2:error] [pid 17486:tid 17486] [client 141.101.98.47:11736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "versahealthcare.com"] [uri "/.env.dev"] [unique_id "asHR_TNHTFrG4geMpN9VIgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-01 16:27:10
(5 days ago)
[01/Oct/2026:19:27:10 +0300] -- 141.101.98.47 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[01/Oct/2026:19:27:10 +0300] -- 141.101.98.47 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
π§πͺ
voormedia
2026-10-01 10:22:54
(5 days ago)
Accessed trap at '/phpinfo.php'
Web App Attack
Anonymous
2026-10-01 04:38:46
(5 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-30 12:04:21
(6 days ago)
[30/Sep/2026:15:04:20 +0300] -- 141.101.98.47 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[30/Sep/2026:15:04:20 +0300] -- 141.101.98.47 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack