๐ซ๐ท
dynamix
2026-09-26 12:17:23
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 12:08:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 08:08:08.837674 2026] [security2:error] [pid 4051:tid 4157] [client 141.101.98.95:12462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vcschief.org"] [uri "/.env.staging"] [unique_id "are1qMIJA4Z0b1pXPxLfbwAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ALPHANET
2026-09-26 11:24:07
(1 day ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐ซ๐ท
arsonist
2026-09-26 11:22:49
(1 day ago)
[fail2ban]
2026-09-26T11:22:49.455580+00:00 arson caddy[1890453]: {"level":"info","ts":1790421769.45 ...
show more
[fail2ban]
2026-09-26T11:22:49.455580+00:00 arson caddy[1890453]: {"level":"info","ts":1790421769.4555485,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"141.101.98.95","remote_port":"13028","client_ip":"141.101.98.95","proto":"HTTP/2.0","method":"GET","host":"tc14.space","uri":"/.env","headers":{"Pragma":["no-cache"],"X-Forwarded-For":["2a06:98c0:3600::103"],"Cf-Ray":["a411e499392bef0b-LHR"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"X-Forwarded-Proto":["https"],"Cf-Worker":["web-recon-serverless-wp-2.workers.dev"],"Accept-Encoding":["gzip, br"],"Accept-Language":["en-US,en;q=0.9"],"Accept":["*/*"],"Cache-Control":["no-cache"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"tc14.space","
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-26 10:35:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 06:35:49.620400 2026] [security2:error] [pid 24145:tid 24145] [client 141.101.98.95:9500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geauxcowboys.com"] [uri "/.env.production"] [unique_id "aregBTzb-4F18aQF9p3ftAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 08:52:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 04:52:27.401530 2026] [security2:error] [pid 18916:tid 18916] [client 141.101.98.95:10673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.georgegourmet.com"] [uri "/.env.local"] [unique_id "areHy5rtyD8_yb-IBHv5pAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-09-23 01:16:14
(5 days ago)
tcp/443 (5 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-12 06:47:43
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 02:47:39.018906 2026] [security2:error] [pid 3268:tid 3268] [client 141.101.98.95:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.webuildbeaches.com"] [uri "/.env"] [unique_id "aqT1i3cowOmXIPBchs5cigAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.mammazone.it
2026-08-14 17:09:34
(1 month ago)
[Fri Aug 14 19:09:32.797924 2026] [proxy_fcgi:error] [pid 2927020] [client 141.101.98.95:10532] AH01 ...
show more
[Fri Aug 14 19:09:32.797924 2026] [proxy_fcgi:error] [pid 2927020] [client 141.101.98.95:10532] AH01071: Got error 'Primary script unknown'
[Fri Aug 14 19:09:34.179582 2026] [proxy_fcgi:error] [pid 2927020] [client 141.101.98.95:10532] AH01071: Got error 'Primary script unknown'
...
show less
Hacking
๐ง๐ช
madeit
2026-08-08 12:59:31
(1 month ago)
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-07-10 00:15:39
(2 months ago)
ipoac.nl:80 141.101.98.95 - - [10/Jul/2026:02:15:38 +0200] - "GET /wp-admin/install.php?step=1 HTTP/ ...
show more
ipoac.nl:80 141.101.98.95 - - [10/Jul/2026:02:15:38 +0200] - "GET /wp-admin/install.php?step=1 HTTP/1.1" 302 955 "-" "http://-/wp-admin/install.php?step=1"
show less
Bad Web Bot
๐บ๐ธ
wimaxnz
2026-06-20 08:22:27
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-06-14 21:59:04
(3 months ago)
Auto-ban: >3000 req/min op 2026-06-14
Web App Attack
SSH
Hacking
๐บ๐ธ
wimaxnz
2026-06-08 00:17:54
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐บ๐ธ
wimaxnz
2026-06-01 07:41:10
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan