๐ฉ๐ช
altenglaner
2026-10-07 16:37:38
(1 hour ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
crooze.net
2026-10-07 16:00:39
(2 hours ago)
141.101.98.82 - - [07/Oct/2026:12:00:39 -0400] "GET /wp-config.php.bak HTTP/1.1" 301 162 "-" "Mozill ...
show more
141.101.98.82 - - [07/Oct/2026:12:00:39 -0400] "GET /wp-config.php.bak HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 15:42:42
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 11:42:32.042891 2026] [security2:error] [pid 29803:tid 29803] [client 141.101.98.82:13518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title23.com"] [uri "/.env.local"] [unique_id "asZoaNqMPaBl5dODxZOmzgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 13:13:58
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 09:13:52.357508 2026] [security2:error] [pid 7562:tid 7575] [client 141.101.98.82:11072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotairwelder.com"] [uri "/.env.save"] [unique_id "asZFkLcMCCj794kJJTzqZQAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 12:07:16
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:07:07.449205 2026] [security2:error] [pid 17157:tid 17157] [client 141.101.98.82:10720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelwakim.com"] [uri "/.env.dev"] [unique_id "asY164wdPb_ZQZLAwOjfhwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 10:06:54
(7 hours ago)
141.101.98.82 - - [07/Oct/2026:07:06:52 -0300] "GET /.git/HEAD HTTP/1.1" 500 572 "-" "Mozilla/5.0 (X ...
show more
141.101.98.82 - - [07/Oct/2026:07:06:52 -0300] "GET /.git/HEAD HTTP/1.1" 500 572 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-10-07 06:01:25
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:01:19.951724 2026] [security2:error] [pid 27368:tid 27368] [client 141.101.98.82:12715] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vpatech.com"] [uri "/.svn/entries"] [unique_id "asXgLzGpAF-033byHp_CAAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 04:15:27
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:15:19.373980 2026] [security2:error] [pid 15713:tid 15713] [client 141.101.98.82:10418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mountainjaytherapy.com"] [uri "/.env.save"] [unique_id "asXHV13Q-xH922IJmMBpRwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
hxsain
2026-10-07 03:57:30
(14 hours ago)
Blocked by UFW [443/tcp] | SPT: 64362 | TTL: 56 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefi ...
show more
Blocked by UFW [443/tcp] | SPT: 64362 | TTL: 56 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฌ๐ง
consul.to
2026-10-07 02:57:40
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 01:12:05
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:11:51.814401 2026] [security2:error] [pid 11385:tid 11385] [client 141.101.98.82:12759] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stukabird.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stukabird.com"] [uri "/index.php.bak"] [unique_id "asWcV5q1RYDXRJcGpDl2VwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:37:45
(18 hours ago)
(mod_security) mod_security (id:949110) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:37:37.021673 2026] [security2:error] [pid 952:tid 952] [client 141.101.98.82:12705] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/.env.dev"] [unique_id "asWGQSYBVU61PuncUqm1hgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-06 20:11:45
(21 hours ago)
[06/Oct/2026:23:11:45 +0300] -- 141.101.98.82 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[06/Oct/2026:23:11:45 +0300] -- 141.101.98.82 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /config.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-06 14:25:32
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:11:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:11:41.350265 2026] [security2:error] [pid 2731:tid 2731] [client 141.101.98.82:9233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "surveyiowa.com"] [uri "/.env.local"] [unique_id "asTlfazO_BKBc8-HcsrnvwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack