๐ณ๐ฑ
BlueWire Hosting
2026-10-08 02:10:34
(6 minutes ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:31:55
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:31:40.681434 2026] [security2:error] [pid 28735:tid 28735] [client 141.101.99.116:11457] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radtraininginc.com"] [uri "/.git/HEAD"] [unique_id "asbWXFj-6qQs0I4-2qGc9QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:07:56
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:07:48.539957 2026] [security2:error] [pid 17912:tid 17912] [client 141.101.99.116:13207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "televisonic.com"] [uri "/.git/config"] [unique_id "asbCtNoYovJHcj2L_2Ri5gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 21:16:16
(5 hours ago)
[08/Oct/2026:00:16:15 +0300] -- 141.101.99.116 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[08/Oct/2026:00:16:15 +0300] -- 141.101.99.116 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:10:26
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:10:19.032662 2026] [security2:error] [pid 28845:tid 28845] [client 141.101.99.116:11481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "partypromdress.com"] [uri "/.env.old"] [unique_id "asa1OzVEp5HF91BUMewyXwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
p0tatosmash3r
2026-10-07 18:19:07
(7 hours ago)
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration ...
show more
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-10-07 17:44:35
(8 hours ago)
2026/10/07 11:34:55 [error] 3693534#3693534: *113811 [client 141.101.99.116] ModSecurity: Access den ...
show more
2026/10/07 11:34:55 [error] 3693534#3693534: *113811 [client 141.101.99.116] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.30.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yobookz.com"] [uri "/.git/HEAD"] [unique_id "179137289513.654536"] [ref ""], client: 141.101.99.116, server: yobookz.com, request: "GET /.git/HEAD HTTP/2.0", host: "yobookz.com"
2026/10/07 17:44:28 [error] 3693531#3693531: *124098 [client 141.101.99.116] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecur
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-07 12:07:07
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:07:00.838820 2026] [security2:error] [pid 15230:tid 15230] [client 141.101.99.116:9919] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelwakim.com"] [uri "/.env.local"] [unique_id "asY15Cj3P8KEYHFSNjzajwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 09:48:09
(16 hours ago)
141.101.99.116 - - [07/Oct/2026:06:48:05 -0300] "GET /wp-config.php.bak HTTP/2.0" 404 1117 "-" "Mozi ...
show more
141.101.99.116 - - [07/Oct/2026:06:48:05 -0300] "GET /wp-config.php.bak HTTP/2.0" 404 1117 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-07 09:39:41
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:39:34.193070 2026] [security2:error] [pid 16984:tid 16984] [client 141.101.99.116:9649] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.tonydelov.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.tonydelov.com"] [uri "/index.php.bak"] [unique_id "asYTVgnmvGacQgOkhN6LlQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 05:22:58
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:22:52.050597 2026] [security2:error] [pid 1679:tid 1679] [client 141.101.99.116:14203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffautry.com"] [uri "/wp-config.php"] [unique_id "asXXLMlQf15ZbD1QkSeIyQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 04:44:28
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:44:23.227842 2026] [security2:error] [pid 10923:tid 10923] [client 141.101.99.116:13782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blacksheepoffroad.com"] [uri "/.htaccess"] [unique_id "asXOJync3LONKzIxt7s2EQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-07 02:46:09
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:08:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:08:41.765714 2026] [security2:error] [pid 1098:tid 1098] [client 141.101.99.116:10735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-cook-islands.com"] [uri "/wp-config.php"] [unique_id "asWpqVP7FdWtFqTFKCRmIwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 22:12:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:12:40.395068 2026] [security2:error] [pid 23388:tid 23388] [client 141.101.99.116:11923] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leeu100.com"] [uri "/.env.local"] [unique_id "asVyWId0l0Uoz0PeAlQPOAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack