๐ช๐ธ
bohl-aiG5aef
2026-10-08 02:49:38
(2 hours ago)
Suricata Alert [SID:2031502] ET INFO Request to Hidden Environment File - Inbound
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 01:18:58
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:18:26.376702 2026] [security2:error] [pid 9276:tid 9276] [client 141.101.99.100:11065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnlittlehorn.com"] [uri "/.git/config"] [unique_id "asbvYuM7ii6trVVWRzCJbAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:59:56
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:59:52.635139 2026] [security2:error] [pid 11203:tid 11203] [client 141.101.99.100:10548] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||civilwarscout.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "civilwarscout.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asbrCK9mBCf9Bgt8selKOAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 00:53:25
(4 hours ago)
Sensitive Configuration File Disclosure.
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 00:12:54
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:12:21.751291 2026] [security2:error] [pid 23526:tid 23535] [client 141.101.99.100:10507] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pattinauction.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pattinauction.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asbf5eVKUgM-nzSURvChgAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 22:39:22
(7 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
crooze.net
2026-10-07 21:53:32
(7 hours ago)
141.101.99.100 - - [07/Oct/2026:17:53:32 -0400] "GET /.git/HEAD HTTP/1.1" 301 162 "-" "Mozilla/5.0 ( ...
show more
141.101.99.100 - - [07/Oct/2026:17:53:32 -0400] "GET /.git/HEAD HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 20:05:41
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:05:28.304478 2026] [security2:error] [pid 13722:tid 13722] [client 141.101.99.100:11827] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mylesmitchell.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mylesmitchell.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asamCIZ46b8vySTlGNLLJAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 19:29:16
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:29:09.642751 2026] [security2:error] [pid 474:tid 474] [client 141.101.99.100:11794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fancycleaners.com"] [uri "/wp-config.php.bak"] [unique_id "asadhW0Bf_tSuDWeNRZAygAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 19:10:50
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:10:43.133332 2026] [security2:error] [pid 25414:tid 25414] [client 141.101.99.100:9641] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rodzillacharters.com"] [uri "/.git/HEAD"] [unique_id "asaZM2NE0n8iVPYejShkcQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 07:41:37
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 03:41:30.180185 2026] [security2:error] [pid 4378:tid 4378] [client 141.101.99.100:9388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffautry.com"] [uri "/wp-config.php.save"] [unique_id "asX3qlFGTxt3nOmtB3OBKQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 05:38:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:38:31.157058 2026] [security2:error] [pid 941:tid 941] [client 141.101.99.100:12339] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stukabird.com"] [uri "/.env"] [unique_id "asXa1wZjaSLEvVIzcCM2YgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 03:44:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:44:17.418708 2026] [security2:error] [pid 7952:tid 7952] [client 141.101.99.100:9340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vpatech.com"] [uri "/.env.backup"] [unique_id "asXAEeZO4eZRoRQ6CtZGdQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-07 03:15:17
(1 day ago)
[WedOct0705:15:07.7230342026][security2:error][pid2989144:tid2989157][client141.101.99.100:0]ModSecu ...
show more
[WedOct0705:15:07.7230342026][security2:error][pid2989144:tid2989157][client141.101.99.100:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"4hosts.net\"][uri\"/.docker/config.json\"][unique_id\"asW5O0S6gofwBML2Guv5dAAAAAs\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 00:22:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 20:22:28.421910 2026] [security2:error] [pid 22855:tid 22855] [client 141.101.99.100:12467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.lindenwoodpark.org"] [uri "/wp-config.php"] [unique_id "asWQxP9InBi6trmXxR9GeQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack