๐บ๐ธ
TPI-Abuse
2026-10-07 23:57:12
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:56:56.739371 2026] [security2:error] [pid 6213:tid 6213] [client 141.101.99.121:10021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "almudenastrust.com"] [uri "/.git/HEAD"] [unique_id "asbcSB2xySaClL4Br1Gj8QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:31:48
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:31:33.712568 2026] [security2:error] [pid 28281:tid 28281] [client 141.101.99.121:11056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radtraininginc.com"] [uri "/.env.local"] [unique_id "asbWVd5ea4JjlcefE19R9gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 21:49:04
(20 hours ago)
[08/Oct/2026:00:49:03 +0300] -- 141.101.99.121 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[08/Oct/2026:00:49:03 +0300] -- 141.101.99.121 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /index.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 20:45:20
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:45:12.974056 2026] [security2:error] [pid 26478:tid 26478] [client 141.101.99.121:13834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.voodooshop.com"] [uri "/.env.save"] [unique_id "asavWJUtaBUyUMJL_jLTkAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
p0tatosmash3r
2026-10-07 18:21:04
(1 day ago)
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration ...
show more
Honeypot-observed malicious activity: unauth data-store / config enumeration; data-store enumeration.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-07 11:39:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 07:39:48.343017 2026] [security2:error] [pid 10579:tid 10579] [client 141.101.99.121:12643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lidart.org"] [uri "/.env.backup"] [unique_id "asYvhAO02qCxRG0TR2ZrcgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 09:03:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:03:32.679932 2026] [security2:error] [pid 22136:tid 22136] [client 141.101.99.121:13827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffautry.com"] [uri "/.env.backup"] [unique_id "asYK5HUPM53Ab0y90ovQswAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 06:56:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:56:39.223017 2026] [security2:error] [pid 15457:tid 15457] [client 141.101.99.121:12314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mountainjaytherapy.com"] [uri "/wp-config.php.old"] [unique_id "asXtJ2fH8jgCH2CsiwP5fQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
DrLex0
2026-10-07 06:16:49
(1 day ago)
Probing for various exploits, distributed attack from CloudFlare reverse proxy crap which is conveni ...
show more
Probing for various exploits, distributed attack from CloudFlare reverse proxy crap which is conveniently whitelisted by AbuseIPDB.
141.101.99.121 443 - [07/Oct/2026:06:16:49 +0000] "GET /index.php~ HTTP/1.1" 404 7511 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 06:01:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 02:01:23.353269 2026] [security2:error] [pid 28436:tid 28436] [client 141.101.99.121:12840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vpatech.com"] [uri "/.htaccess"] [unique_id "asXgM-9bWcgaSbv0fYB4-wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:20:57
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:20:31.937715 2026] [security2:error] [pid 25986:tid 25986] [client 141.101.99.121:9436] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/%2eenv"] [unique_id "asWCP2y6wC8wjcjXk7WYfAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 17:02:11
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 13:02:04.895752 2026] [security2:error] [pid 1495:tid 1495] [client 141.101.99.121:12209] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desertalfas.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desertalfas.org"] [uri "/index.php.bak"] [unique_id "asKGjJrVpFyWzoT0ge_KCgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-02 17:33:30
(6 days ago)
[02/Oct/2026:20:33:29 +0300] -- 141.101.99.121 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[02/Oct/2026:20:33:29 +0300] -- 141.101.99.121 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:59:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:59:15.866790 2026] [security2:error] [pid 4462:tid 4462] [client 141.101.99.121:11974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gpaarch.com"] [uri "/.env.staging"] [unique_id "ar5ZI-OXCEAN0re8bLPQYgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:22:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.121 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:21:56.469675 2026] [security2:error] [pid 30370:tid 30370] [client 141.101.99.121:11007] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "westernmassaa.net"] [uri "/.env"] [unique_id "ar5QZAdTvfqa0qMlTBEgVgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack