๐บ๐ธ
TPI-Abuse
2026-10-06 16:07:16
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:07:04.030008 2026] [security2:error] [pid 16070:tid 16070] [client 141.101.98.9:10093] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "microscope.modelengines.info"] [uri "/.env.staging"] [unique_id "asUcqMpdcnEXrikzhRCjsgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-06 15:53:16
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-06 15:15:26
(2 hours ago)
[Wed Oct 07 02:15:25.678980 2026] [security2:error] [pid 264013] [client 141.101.98.9:12143] [client ...
show more
[Wed Oct 07 02:15:25.678980 2026] [security2:error] [pid 264013] [client 141.101.98.9:12143] [client 141.101.98.9] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/index.php~"] [unique_id "asUQjXJa1wam8jzTuu_w2AAAACc"]
...
show less
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-10-06 15:10:59
(2 hours ago)
vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:11:36
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:11:27.744937 2026] [security2:error] [pid 24885:tid 24885] [client 141.101.98.9:12580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenolangroup.llc"] [uri "/.env.dev"] [unique_id "asTzf9HzQW__0zjjGvuPFgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:58:38
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:58:19.744390 2026] [security2:error] [pid 29985:tid 29985] [client 141.101.98.9:13511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabbathschoolguide.com"] [uri "/.env.dev"] [unique_id "asTiW4MmB5CEkwySkD7oAQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:10:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:10:20.955800 2026] [security2:error] [pid 23344:tid 23344] [client 141.101.98.9:13141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "honeybeeplace.com"] [uri "/.env.bak"] [unique_id "asTXHMDhJVZC0_4H73TIZAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:17:37
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:17:18.854830 2026] [security2:error] [pid 27791:tid 27791] [client 141.101.98.9:10257] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desertalfas.org"] [uri "/wp-config.php.old"] [unique_id "asTKrpNs7lbjGC68LpsCRgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:36:54
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:36:48.024488 2026] [security2:error] [pid 25978:tid 25978] [client 141.101.98.9:13347] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saramics.net"] [uri "/.env.local"] [unique_id "asTBMMSKeGMpJtFVFbeG1AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 02:09:59
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 22:09:51.251254 2026] [security2:error] [pid 24954:tid 24954] [client 141.101.98.9:11014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horsesaw.com"] [uri "/.env.production"] [unique_id "asRYb1xl88o02xFxjaimhgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-05 22:37:40
(19 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 03:36:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 23:36:17.030962 2026] [security2:error] [pid 23258:tid 23258] [client 141.101.98.9:14147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peregrineproject.com"] [uri "/wp-config.php.bak"] [unique_id "asMbMcE5FbGYORvTzMyIgQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-04 08:59:36
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, path_traversal, git_exposure, credential_file, config_backup. Observed by 1 sensor(s); 18 hits.
show less
Web App Attack
๐ซ๐ฎ
abdubhai
2026-10-02 05:37:01
(4 days ago)
141.101.98.9 - - [02/Oct/2026:10
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-01 16:06:21
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:06:13.133320 2026] [security2:error] [pid 14403:tid 14403] [client 141.101.98.9:10267] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bizzybeejunkremoval.com"] [uri "/.env.local"] [unique_id "ar6E9dUuD9FF6Nk_DV2HoQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack