๐ฎ๐น
Inartis
2026-10-06 16:14:11
(1 hour ago)
141.101.98.80 - - [06/Oct/2026:18:14:09 +0200] "GET /.env.backup HTTP/1.1" 302 457 "-" "Mozilla/5.0 ...
show more
141.101.98.80 - - [06/Oct/2026:18:14:09 +0200] "GET /.env.backup HTTP/1.1" 302 457 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐ช
CG
2026-10-06 14:33:54
(3 hours ago)
Web application attack, Automated scan
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-06 14:30:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:30:13.146030 2026] [security2:error] [pid 30727:tid 30823] [client 141.101.98.80:10163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greencitymethods.com"] [uri "/.env.local"] [unique_id "asUF9Vvm311epDWKYzKShQAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:58:08
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:57:58.975313 2026] [security2:error] [pid 10011:tid 10011] [client 141.101.98.80:12754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcarrollcommunications.com"] [uri "/.env.local"] [unique_id "asTwVjRUQycdfQY1SsKD3wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-06 12:35:44
(5 hours ago)
[06/Oct/2026:15:35:43 +0300] -- 141.101.98.80 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[06/Oct/2026:15:35:43 +0300] -- 141.101.98.80 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /credentials.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:53:14
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:53:00.536336 2026] [security2:error] [pid 14858:tid 14858] [client 141.101.98.80:14136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-cayman.com"] [uri "/.git/config"] [unique_id "asThHJTonhKctZHeG-zP8wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:10:35
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:10:20.168666 2026] [security2:error] [pid 23529:tid 23529] [client 141.101.98.80:13966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honeybeeplace.com"] [uri "/.env.dev"] [unique_id "asTXHDFzNwXqGEWH0wP-cwAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-06 10:53:57
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:39:27
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:39:09.349918 2026] [security2:error] [pid 1989:tid 1989] [client 141.101.98.80:11519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessiedavison.com"] [uri "/.env.save"] [unique_id "asTPzU3ZFsO5y3bPsbpfFwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:44:05
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:43:55.422117 2026] [security2:error] [pid 25695:tid 25695] [client 141.101.98.80:12408] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||majesticsolutions.co|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "majesticsolutions.co"] [uri "/index.php.bak"] [unique_id "asTC2-4sHnlhdZhCIiB64QAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:45:46
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:45:42.806501 2026] [security2:error] [pid 19622:tid 19622] [client 141.101.98.80:12533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtcdesigns.com"] [uri "/.git/HEAD"] [unique_id "asSnJsTLR0tHPR9Z_y76NwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-05 23:01:14
(18 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 16:10:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 12:10:16.105387 2026] [security2:error] [pid 24249:tid 24279] [client 141.101.98.80:9904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howilearnedtodanceintherain.com.teritemme.com"] [uri "/.git/config"] [unique_id "asPL6F1xaTaiHmszvSTSuwAAAZg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 08:35:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 04:35:38.431659 2026] [security2:error] [pid 19644:tid 19644] [client 141.101.98.80:11467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "steveleeds.com"] [uri "/.env.bak"] [unique_id "asNhWqUGpmhgLs3brjMJkAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 07:54:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:54:44.914734 2026] [security2:error] [pid 7500:tid 7500] [client 141.101.98.80:9779] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "insidepublications.com"] [uri "/.env.local"] [unique_id "asNXxGr8_ptiqlg6MpN_QwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack