πΊπΈ
TPI-Abuse
2026-10-07 23:06:22
(17 minutes ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:06:14.016603 2026] [security2:error] [pid 16057:tid 16057] [client 141.101.98.75:14212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1st-advantage-arkansas-real-estate-school.com"] [uri "/.env.production"] [unique_id "asbQZh-sUVlcVgSoSQa-agAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 22:34:57
(48 minutes ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:34:42.524593 2026] [security2:error] [pid 2267:tid 2267] [client 141.101.98.75:14065] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||outofthebluephotography.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "outofthebluephotography.com"] [uri "/index.php.bak"] [unique_id "asbJAj1UDfVkmAqQ6nAPIgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 22:03:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:03:28.154258 2026] [security2:error] [pid 13763:tid 13763] [client 141.101.98.75:9610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "televisonic.com"] [uri "/.git/HEAD"] [unique_id "asbBsDf3AJonDID0fsJ0YgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-10-07 21:59:25
(1 hour ago)
Auto-ban: >3000 req/min op 2026-10-07
Web App Attack
SSH
Hacking
π³π±
Alt255
2026-10-07 21:26:09
(1 hour ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.98.75 - - [07/Oct/2026:23:26:07 +0200] "GET /.git/HEAD HTTP/1.1" 301 585 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 20:06:41
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:06:34.694971 2026] [security2:error] [pid 29455:tid 29455] [client 141.101.98.75:11789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title23.com"] [uri "/.env.local"] [unique_id "asamSoodW5PhV0sv5TN63gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 17:24:27
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 13:24:18.344854 2026] [security2:error] [pid 7922:tid 7922] [client 141.101.98.75:9780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tonydelov.com"] [uri "/.git/config"] [unique_id "asaAQugbrRLbHLTb-JH6hwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
Roper123
2026-10-07 12:57:06
(10 hours ago)
Web app exploits
Web App Attack
π«π·
dynamix
2026-10-07 12:29:02
(10 hours ago)
Multiple WAF Violations
Web App Attack
π¬π§
consul.to
2026-10-07 07:39:40
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 06:51:51
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:51:38.905401 2026] [security2:error] [pid 9334:tid 9334] [client 141.101.98.75:14007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greed.ee"] [uri "/.env.dev"] [unique_id "asXr-sn52geosJr2n06TjwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 06:07:42
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:07:33.705837 2026] [security2:error] [pid 23450:tid 23450] [client 141.101.98.75:11874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jsommer.com"] [uri "/.env.old"] [unique_id "asXhpfHoVDEBBpiK9vw-TQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-07 02:25:20
(20 hours ago)
[07/Oct/2026:05:25:20 +0300] -- 141.101.98.75 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[07/Oct/2026:05:25:20 +0300] -- 141.101.98.75 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 22:55:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:55:28.301595 2026] [security2:error] [pid 902:tid 918] [client 141.101.98.75:12080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertagmetairie.com"] [uri "/.env.save"] [unique_id "asV8YGYfXIrdVmgwRJSUPgAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 16:34:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:34:06.077033 2026] [security2:error] [pid 13221:tid 13221] [client 141.101.98.75:10152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toytractorrepair.com"] [uri "/.htaccess"] [unique_id "asUi_v-_asuzPwhJJu1yWgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack