๐บ๐ธ
TPI-Abuse
2026-09-30 09:50:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:50:03.482188 2026] [security2:error] [pid 20432:tid 20432] [client 141.101.98.64:12311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathiasaspelin.com"] [uri "/.env.local"] [unique_id "arzbSzseUd8Anh8sfRfU8gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:27:02
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:26:53.733685 2026] [security2:error] [pid 3658:tid 3658] [client 141.101.98.64:9836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "markthwaite.com"] [uri "/.git/HEAD"] [unique_id "arzV3Y5_5e0zlBoEvFhkmgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 07:37:06
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:36:58.247857 2026] [security2:error] [pid 30950:tid 30950] [client 141.101.98.64:13444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "futuresgrowhere.com"] [uri "/.git/HEAD"] [unique_id "ary8GjXHz2vYmEFRa5PWQgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 05:28:44
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:28:40.615641 2026] [security2:error] [pid 8897:tid 8897] [client 141.101.98.64:11200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jaragoodrich.com"] [uri "/.env.local"] [unique_id "aryeCKHdTa3AQMMlb9nizwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-29 20:15:25
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 13:12:47
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:12:40.193180 2026] [security2:error] [pid 28245:tid 29095] [client 141.101.98.64:13631] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||prominentregroup.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "prominentregroup.com"] [uri "/index.php.bak"] [unique_id "aru5SBf_Ga-blh2-ybTllQAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 09:54:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 05:54:27.556426 2026] [security2:error] [pid 4611:tid 4641] [client 141.101.98.64:11246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howardhallis.com"] [uri "/.git/config"] [unique_id "aruK09-xYQtcVfb7C8EdfgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 05:48:37
(1 day ago)
[29/Sep/2026:08:48:36 +0300] -- 141.101.98.64 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[29/Sep/2026:08:48:36 +0300] -- 141.101.98.64 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐น๐ผ
kk_it_man
2026-09-29 05:43:01
(1 day ago)
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-28 16:04:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 12:04:48.655074 2026] [security2:error] [pid 14694:tid 14694] [client 141.101.98.64:12100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.trancelucid.com"] [uri "/.env.staging"] [unique_id "arqQIAITsRLVRqjiodx0MQAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 15:24:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 11:24:01.474268 2026] [security2:error] [pid 21651:tid 21651] [client 141.101.98.64:12827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dennisangellismusic.com"] [uri "/.env.production"] [unique_id "arqGkXKBLZolOe3JQf3_NwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-09-28 09:22:22
(2 days ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-28 08:05:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 04:05:51.977088 2026] [security2:error] [pid 14020:tid 14020] [client 141.101.98.64:13808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gpusa-ca.com"] [uri "/.env.production"] [unique_id "arof375mUbmolvnK7O4bWgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-09-28 07:55:25
(2 days ago)
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kinesk ...
show more
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kineskinja)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-26 14:44:08
(3 days ago)
GET /.env HTTP/1.1
...
Web App Attack