π²πΎ
Rizzy
2026-10-11 11:50:14
(2 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-11 11:27:42
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 11 07:27:34.965128 2026] [security2:error] [pid 20917:tid 21036] [client 141.101.99.132:9906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "giftsandgarland.com"] [uri "/.env"] [unique_id "astypq8UFUWCon-c9MKkqgAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-11 09:59:23
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 11 05:59:19.550379 2026] [security2:error] [pid 8632:tid 8632] [client 141.101.99.132:12600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dartylife.com"] [uri "/.env.old"] [unique_id "astd9zh7l8ZZb6d49t0QrwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-11 09:50:30
(4 hours ago)
[11/Oct/2026:12:50:30 +0300] -- 141.101.99.132 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[11/Oct/2026:12:50:30 +0300] -- 141.101.99.132 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2026-10-11 08:50:37
(5 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π©πͺ
yitzhaq
2026-10-11 08:23:03
(6 hours ago)
141.101.99.132 - - [11/Oct/2026:10:22:53 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 498 "-" "Mozil ...
show more
141.101.99.132 - - [11/Oct/2026:10:22:53 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 498 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
141.101.99.132 - - [11/Oct/2026:10:22:55 +0200] "GET /.index.php.swp HTTP/1.1" 404 498 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:123.0) Gecko/20100101 Firefox/123.0"
141.101.99.132 - - [11/Oct/2026:10:22:56 +0200] "GET /index%20copy.php HTTP/1.1" 404 522 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
Brute-Force
π©πͺ
altenglaner
2026-10-10 23:44:39
(15 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 16:37:26
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 12:37:20.092649 2026] [security2:error] [pid 22792:tid 22792] [client 141.101.99.132:9980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mikebenson.com"] [uri "/.git/config"] [unique_id "asppwCQceP-Ow7iLWL-V7gAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 13:33:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 09:33:28.037667 2026] [security2:error] [pid 661:tid 661] [client 141.101.99.132:9718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cortona.ws"] [uri "/wp-config.php"] [unique_id "aso-qBZAPErjPVUTyeDD7QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 12:39:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 08:39:22.537462 2026] [security2:error] [pid 12237:tid 12237] [client 141.101.99.132:12334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fromthehandofgodministry.org"] [uri "/.env"] [unique_id "asox-hnhfaSmfOyHMusoiQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 11:30:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 07:30:23.830857 2026] [security2:error] [pid 27338:tid 27338] [client 141.101.99.132:12258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twangcaster.com"] [uri "/.git/config"] [unique_id "asohz-XK-Fy9FzB4T3exqwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 05:29:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 01:29:06.915150 2026] [security2:error] [pid 17072:tid 17072] [client 141.101.99.132:13126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oaklands1.com"] [uri "/.env.staging"] [unique_id "asnNIl17LhhspBkL2ODGowAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-10 04:16:26
(1 day ago)
[10/Oct/2026:07:16:26 +0300] -- 141.101.99.132 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[10/Oct/2026:07:16:26 +0300] -- 141.101.99.132 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.save HTTP/1.1
show less
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-10-10 03:43:32
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 23:13:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 19:13:17.153382 2026] [security2:error] [pid 30411:tid 30411] [client 141.101.99.132:9356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title33.com"] [uri "/.env.dev"] [unique_id "asl1DSgM2GnGy8Ju0VvKGwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack