๐ฉ๐ช
4server
2026-10-04 08:25:20
(3 hours ago)
[SunOct0410:25:15.0736282026][security2:error][pid661719:tid661761][client141.101.99.141:0]ModSecuri ...
show more
[SunOct0410:25:15.0736282026][security2:error][pid661719:tid661761][client141.101.99.141:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"[a-z0-9]~\$\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1158\"][id\"390581\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-DataLeakage-attempttoaccessbackupfile\(disablethisruleifyourequireaccesstofilesthatendwithatilde\)\"][severity\"CRITICAL\"][hostname\"gustotondo.ch\"][uri\"/index.php~\"][unique_id\"asINayETy0L1apvunBUm9QAAAIA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:28:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:28:19.442065 2026] [security2:error] [pid 13197:tid 13197] [client 141.101.99.141:10173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.directoryofdrugs.com"] [uri "/.env.local"] [unique_id "ar5f86WhBcjv_qnpHpRYKwAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 05:52:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:52:33.709586 2026] [security2:error] [pid 11673:tid 11673] [client 141.101.99.141:12232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vrbsroma.com"] [uri "/.env.backup"] [unique_id "ar31IWWAfg5QX20IkO8VTQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 01:44:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:44:29.902215 2026] [security2:error] [pid 29897:tid 29897] [client 141.101.99.141:9519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nancybcatering.com"] [uri "/.env.production"] [unique_id "ar26_SdkBM2eatbwwXmXLwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-10-01 01:13:37
(3 days ago)
vulnerability scan
Web App Attack
๐ฎ๐น
Inartis
2026-09-30 22:44:19
(3 days ago)
141.101.99.141 - - [01/Oct/2026:00:44:18 +0200] "GET /.env.backup HTTP/2.0" 403 0 "-" "Mozilla/5.0 ( ...
show more
141.101.99.141 - - [01/Oct/2026:00:44:18 +0200] "GET /.env.backup HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:24:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:24:37.857416 2026] [security2:error] [pid 25880:tid 25880] [client 141.101.99.141:9865] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twogocamping.com"] [uri "/.env.staging"] [unique_id "ar03xUDtP2aiLaB3T19yoQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:55:35
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:55:30.540965 2026] [security2:error] [pid 26196:tid 26200] [client 141.101.99.141:10282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.infectioncontrolsys.com"] [uri "/.env.backup"] [unique_id "ar0GwnfNQRFUb5YEMkhm3wAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 06:00:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:00:45.265997 2026] [security2:error] [pid 32268:tid 32268] [client 141.101.99.141:10559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sophcomp.com"] [uri "/.svn/entries"] [unique_id "aryljb4wZ-WcAiKKM-MMqQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
lns.bz
2026-09-30 05:46:39
(4 days ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 14:39:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 10:38:59.418656 2026] [security2:error] [pid 28227:tid 29029] [client 141.101.99.141:12482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crosscountry.ahsdistance.org"] [uri "/.env.production"] [unique_id "arvNg_tutBTQST4iEtA4cQAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 12:50:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:50:42.620163 2026] [security2:error] [pid 31572:tid 31572] [client 141.101.99.141:13533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mywheatgrass.com"] [uri "/.env.backup"] [unique_id "aru0IltgRGA6ma9DkAaWbwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 04:05:21
(5 days ago)
[29/Sep/2026:07:05:21 +0300] -- 141.101.99.141 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[29/Sep/2026:07:05:21 +0300] -- 141.101.99.141 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /wp-config.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-09-27 11:00:15
(1 week ago)
141.101.99.141 - - [27/Sep/2026:16:30:15 +0530] "GET /wp-content/plugins/woocommerce/readme.txt HTTP ...
show more
141.101.99.141 - - [27/Sep/2026:16:30:15 +0530] "GET /wp-content/plugins/woocommerce/readme.txt HTTP/2.0" 404 8194 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
show less
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-09-26 16:51:35
(1 week ago)
141.101.99.141 - - [26/Sep/2026:22:21:34 +0530] "GET /wp-content/plugins/woocommerce/readme.txt HTTP ...
show more
141.101.99.141 - - [26/Sep/2026:22:21:34 +0530] "GET /wp-content/plugins/woocommerce/readme.txt HTTP/2.0" 404 8194 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0"
show less
Web App Attack