๐จ๐ฆ
Roper123
2026-10-07 12:55:01
(2 hours ago)
Web app exploits
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 09:32:15
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:32:02.841609 2026] [security2:error] [pid 2534:tid 2534] [client 141.101.98.57:14206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelwakim.com"] [uri "/.git/HEAD"] [unique_id "asYRkqsN0LVmhxWPjobp5QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 05:29:45
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:29:38.379904 2026] [security2:error] [pid 5930:tid 5930] [client 141.101.98.57:11509] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdromline.com"] [uri "/.git/config"] [unique_id "asXYwp2Igq3QFwz3lS6dxAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 05:08:24
(10 hours ago)
[07/Oct/2026:08:08:23 +0300] -- 141.101.98.57 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[07/Oct/2026:08:08:23 +0300] -- 141.101.98.57 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /credentials.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 22:10:42
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:10:34.447113 2026] [security2:error] [pid 19335:tid 19335] [client 141.101.98.57:9846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leeu100.com"] [uri "/.env.production"] [unique_id "asVx2m3w0pw6us8uYsnZ8QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-06 21:59:49
(17 hours ago)
Auto-ban: >3000 req/min op 2026-10-06
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-06 16:14:24
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:14:18.097081 2026] [security2:error] [pid 2448112:tid 2448134] [client 141.101.98.57:13315] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "providencetheological.net"] [uri "/.env.bak"] [unique_id "asUeWsmq67l8ndliSpCUvQAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:30:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:30:00.164127 2026] [security2:error] [pid 32397:tid 32397] [client 141.101.98.57:13993] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wedemandavote.com"] [uri "/.env.bak"] [unique_id "asUF6LrhwjSxsMPsKyxMawAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-06 12:14:21
(1 day ago)
[TueOct0614:14:14.5907162026][security2:error][pid3654297:tid3654422][client141.101.98.57:0]ModSecur ...
show more
[TueOct0614:14:14.5907162026][security2:error][pid3654297:tid3654422][client141.101.98.57:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"hosting-royal.ch\"][uri\"/wp-config.php\"][unique_id\"asTmFkNEkzgxP1XMeg30LAAAAg4\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:57:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:57:33.550633 2026] [security2:error] [pid 13248:tid 13248] [client 141.101.98.57:11530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drainpoultry.com"] [uri "/.env.old"] [unique_id "asTiLeVYKRYUyYgUKSq5fAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-06 10:47:57
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:39:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:39:04.119404 2026] [security2:error] [pid 1960:tid 1960] [client 141.101.98.57:12032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessiedavison.com"] [uri "/.env.production"] [unique_id "asTPyBaWZbOTeadT0rLBAAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-06 10:33:48
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:20:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:19:41.308857 2026] [security2:error] [pid 23720:tid 23720] [client 141.101.98.57:12084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starsmogsandiego.com"] [uri "/.svn/entries"] [unique_id "asTLPbwUM688hgUmSihYPAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:36:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:36:45.074326 2026] [security2:error] [pid 17234:tid 17234] [client 141.101.98.57:13662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiointernational.net"] [uri "/.env.bak"] [unique_id "asTBLVY1S6xmAvROeDvEigAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack