๐บ๐ธ
TPI-Abuse
2026-10-08 13:26:21
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:26:14.400341 2026] [security2:error] [pid 14380:tid 14380] [client 141.101.98.88:13269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "misterflores.com"] [uri "/.env"] [unique_id "aseZ9q0NOom_LkYn0Ry9QgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 09:06:11
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:06:07.316873 2026] [security2:error] [pid 9245:tid 9245] [client 141.101.98.88:12420] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brasscadillac.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brasscadillac.com"] [uri "/index.php.bak"] [unique_id "asdc_7JosdLAO6EzTKl3DQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:45:29
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:45:22.226553 2026] [security2:error] [pid 31015:tid 31015] [client 141.101.98.88:11715] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdijoe.com"] [uri "/wp-config.php"] [unique_id "asdKEhFbslhg1V42WowTggAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:02:07
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:01:59.152528 2026] [security2:error] [pid 12659:tid 12659] [client 141.101.98.88:12458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "act-research.com"] [uri "/.env"] [unique_id "asc_59Onp4U5azKnVxB9FwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-10-08 06:49:11
(6 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐ฉ๐ช
4server
2026-10-08 05:52:11
(7 hours ago)
[ThuOct0807:52:02.4042782026][security2:error][pid1909341:tid1909439][client141.101.98.88:0]ModSecur ...
show more
[ThuOct0807:52:02.4042782026][security2:error][pid1909341:tid1909439][client141.101.98.88:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"martinairsagl.ch\"][uri\"/.env.production\"][unique_id\"ascvgk9X9Q1bBvWGCwewuAAAAIw\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:11:00
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:10:45.269411 2026] [security2:error] [pid 22719:tid 22719] [client 141.101.98.88:12674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fatcaverecords.com"] [uri "/.env"] [unique_id "ascXxeHAEnfchb_taqT9NQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 02:25:45
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 22:25:41.411214 2026] [security2:error] [pid 29819:tid 29821] [client 141.101.98.88:13971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evan-hotel.com"] [uri "/.env.save"] [unique_id "asb_JZY5uDYLmMr2cNYFDgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:19:25
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:18:25.071350 2026] [security2:error] [pid 8321:tid 8321] [client 141.101.98.88:9646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnlittlehorn.com"] [uri "/.env.local"] [unique_id "asbvYaUuoXl8FIx3vMcjjAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 00:34:20
(13 hours ago)
141.101.98.88 - - [08/Oct/2026:02:34:19 +0200] "GET /. HTTP/2.0" 301 169 "-" "Mozilla/5.0 (Macintosh ...
show more
141.101.98.88 - - [08/Oct/2026:02:34:19 +0200] "GET /. HTTP/2.0" 301 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 00:27:53
(13 hours ago)
[08/Oct/2026:03:27:53 +0300] -- 141.101.98.88 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[08/Oct/2026:03:27:53 +0300] -- 141.101.98.88 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.staging HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:55:38
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:55:26.464104 2026] [security2:error] [pid 5101:tid 5101] [client 141.101.98.88:10908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "televisonic.com"] [uri "/wp-config.php.bak"] [unique_id "asa_ziGVcU6ubCeXaU-CxQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 20:24:27
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:24:19.284305 2026] [security2:error] [pid 7868:tid 7868] [client 141.101.98.88:10516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indoorfreeflight.com"] [uri "/.env.dev"] [unique_id "asaqczuEUuC9979YXyuNEgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-07 09:24:35
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-10-07 08:52:05
(1 day ago)
Web attack/malicious scanning detected
Web App Attack