๐ฌ๐ง
OptimusGO
2026-06-28 06:05:48
(10 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-28 07:05:48 UTC
Log evidence:
06/28/2026-07:05:46.981026 [**] [1:1000101:2] SECURITY Port Scan Detected - Multiple Unauthorized Ports [**] [Classification: Attempted Information Leak] [Priority: 1] {TCP} 141.101.98.63:9390 -> 185.127.18.66:2096
06/28/2026-07:05:48.006017 [**] [1:1000101:2] SECURITY Port Scan Detected - Multiple Unauthorized Ports [**] [Classification: Attempted Information Leak] [Priority: 1] {TCP} 141.101.98.63:9390 -> 185.127.18.66:2096
show less
Port Scan
Brute-Force
๐ฌ๐ง
pinguin
2026-06-10 02:03:33
(2 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from GB.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from GB.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /admin/config/common.js
UA: TLM-Audit-Scanner/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-09 02:48:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 22:48:50.538291 2026] [security2:error] [pid 96164:tid 96164] [client 141.101.98.63:10811] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.deubellzebub.com"] [uri "/.env.production"] [unique_id "adcTkrfcLmlBBJZYwl69bAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 23:16:10
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 19:16:02.319157 2026] [security2:error] [pid 2769255:tid 2769255] [client 141.101.98.63:13149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.californiaappraisers.net"] [uri "/.env1"] [unique_id "adbhssek20OymeaiYI4HcwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 21:58:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 17:58:02.297651 2026] [security2:error] [pid 1493361:tid 1493373] [client 141.101.98.63:9423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.goodfridaygolf.com"] [uri "/config/.env.local"] [unique_id "adbPajfd3Dw-YA0-iw0qHAAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 21:32:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 17:32:07.066040 2026] [security2:error] [pid 2981293:tid 2981293] [client 141.101.98.63:11510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.swelpix.com"] [uri "/.env.prod"] [unique_id "adbJVyyPrREDnyRwyFC5mwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 19:57:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 15:57:32.915892 2026] [security2:error] [pid 2841675:tid 2841675] [client 141.101.98.63:10882] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.manosentuayuda.org"] [uri "/.env.docker"] [unique_id "adazLBqqwXFyguqDD1q20QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 14:44:56
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 10:44:44.250698 2026] [security2:error] [pid 2641267:tid 2641267] [client 141.101.98.63:12276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "railsolutions.mx"] [uri "/.env.production.local"] [unique_id "adZp3N2YE_1xR0_beQNE7gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 13:19:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 09:19:33.646380 2026] [security2:error] [pid 2144016:tid 2144016] [client 141.101.98.63:12937] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.zztp.ws"] [uri "/.env.json"] [unique_id "adZV5RA_3zDTsznXjkonkgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 10:04:47
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 06:04:37.797752 2026] [security2:error] [pid 2624005:tid 2624005] [client 141.101.98.63:11552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haarr.net"] [uri "/.env.bak"] [unique_id "adYoNf6VfdrYMr_noBZwWwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 09:23:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 05:23:02.837117 2026] [security2:error] [pid 2134964:tid 2134964] [client 141.101.98.63:12287] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.linuxforpoets.com"] [uri "/var/www/html/.env"] [unique_id "adYedsBjlt5jjw2JA92uDgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 06:57:57
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 02:57:52.287748 2026] [security2:error] [pid 1910384:tid 1910384] [client 141.101.98.63:11107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tulsatvmemories.com"] [uri "/.env.dev.local"] [unique_id "adX8cCVuIWzxjcMi8kMI9wAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 02:45:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 22:44:55.114839 2026] [security2:error] [pid 2257153:tid 2257153] [client 141.101.98.63:10458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sizefinder.com"] [uri "/.env2"] [unique_id "adXBJ_ts2fFe7Zgn1kFN-QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 01:18:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 21:17:48.705781 2026] [security2:error] [pid 1977972:tid 1977972] [client 141.101.98.63:12057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dshgraphics.com"] [uri "/web/.env"] [unique_id "adWsvKIS_ZikyGuVNZFwFgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 19:41:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 15:41:16.360896 2026] [security2:error] [pid 1927017:tid 1927017] [client 141.101.98.63:13581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saboun.com"] [uri "/app/.env"] [unique_id "adVd3GcfUSWC6sjDwfSYPAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack