๐ซ๐ท
dynamix
2026-10-08 11:42:29
(3 minutes ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:02:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:01:49.113005 2026] [security2:error] [pid 8816:tid 8816] [client 141.101.98.98:14222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whodatnation.com"] [uri "/.env.backup"] [unique_id "asc_3eHMNKY2-mbYl00aUwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 05:54:21
(5 hours ago)
WordPress Sensitive System Files Information Disclosure; Sensitive Configuration File Disclosure.
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-10-08 05:16:19
(6 hours ago)
4 attacks on password/key grabbing URLs, env grabbing URLs:
GET /.ssh/id_ed25519 HTTP/1.1
GET /.env. ...
show more
4 attacks on password/key grabbing URLs, env grabbing URLs:
GET /.ssh/id_ed25519 HTTP/1.1
GET /.env.backup HTTP/1.1
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 04:52:50
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:52:30.207371 2026] [security2:error] [pid 1584:tid 1584] [client 141.101.98.98:10587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cnwire.com"] [uri "/.env"] [unique_id "aschjr81q-Wg5uD6noNAZAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 02:35:17
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 22:35:08.840742 2026] [security2:error] [pid 18191:tid 18191] [client 141.101.98.98:11536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neilvboyer.com"] [uri "/.svn/entries"] [unique_id "ascBXCg-IxkeD5N01PTBOQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:21:17
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:21:08.961484 2026] [security2:error] [pid 11426:tid 11426] [client 141.101.98.98:10038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "female.bodybuildbid.com"] [uri "/.env"] [unique_id "asbh9L79uOpzxJfRbxqbqQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 00:04:02
(11 hours ago)
[08/Oct/2026:03:04:01 +0300] -- 141.101.98.98 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[08/Oct/2026:03:04:01 +0300] -- 141.101.98.98 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
Esko
2026-10-07 23:17:18
(12 hours ago)
141.101.98.98 - - [07/Oct/2026:23:17:18 +0000] "GET /.env.local HTTP/1.1" 488 0 "-" "Mozilla/5.0 (Wi ...
show more
141.101.98.98 - - [07/Oct/2026:23:17:18 +0000] "GET /.env.local HTTP/1.1" 488 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:06:26
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:06:19.271577 2026] [security2:error] [pid 13818:tid 13818] [client 141.101.98.98:13345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1st-advantage-arkansas-real-estate-school.com"] [uri "/.env.production"] [unique_id "asbQa0Vm9kUOlf6FRiYu9wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:14:52
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:14:37.189127 2026] [security2:error] [pid 27205:tid 27205] [client 141.101.98.98:13278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grupo-visalud.com"] [uri "/.htaccess"] [unique_id "asbETbV5ggTHudlpxq5AAwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-07 21:49:02
(13 hours ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.98.98 - - [07/Oct/2026:23:49:01 +0200] "GET /.git/config HTTP/1.1" 301 589 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 18:32:50
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 14:32:41.044332 2026] [security2:error] [pid 21078:tid 21078] [client 141.101.98.98:11195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftiptondds.com"] [uri "/.svn/entries"] [unique_id "asaQSUNSdmhz3EkbvfGbtAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-07 14:16:53
(21 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 12:59:54
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:59:46.549761 2026] [security2:error] [pid 32704:tid 32704] [client 141.101.98.98:11989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "envirotreecare.com"] [uri "/.env.local"] [unique_id "asZCQtnLmfBT2phUGsXh4gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack