๐ธ๐ช
nekopavel
2026-10-11 08:51:17
(2 hours ago)
141.101.99.18 - - [11/Oct/2026:10:51:12 +0200]"GET /wp-config.php.bak HTTP/2.0" 499 0"-" thighs.moe ...
show more
141.101.99.18 - - [11/Oct/2026:10:51:12 +0200]"GET /wp-config.php.bak HTTP/2.0" 499 0"-" thighs.moe "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36""0.001" "0.000""London" "GB"
141.101.99.18 - - [11/Oct/2026:10:51:15 +0200]"GET /.env.save HTTP/1.1" 301 162"-" thighs.moe "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36""0.000" "-""London" "GB"
141.101.99.18 - - [11/Oct/2026:10:51:16 +0200]"GET /.env.production HTTP/1.1" 301 162"-" thighs.moe "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36""0.000" "-""London" "GB"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-11 08:20:09
(2 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-11 08:12:47
(2 hours ago)
141.101.99.18 - - [11/Oct/2026:10:12:36 +0200] "GET /wp-config.php.save HTTP/2.0" 404 295 "-" "Mozil ...
show more
141.101.99.18 - - [11/Oct/2026:10:12:36 +0200] "GET /wp-config.php.save HTTP/2.0" 404 295 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
141.101.99.18 - - [11/Oct/2026:10:12:35 +0200] "GET /.kube/config HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
141.101.99.18 - - [11/Oct/2026:10:12:35 +0200] "GET /.netrc HTTP/2.0" 404 363 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
141.101.99.18 - - [11/Oct/2026:10:12:36 +0200] "GET /config.php HTTP/2.0" 404 341 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1"
141.101.99.18 - - [11/Oct/2026:10:12:36 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 404 318 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTM
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-11 03:43:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 23:43:01.324004 2026] [security2:error] [pid 26053:tid 26053] [client 141.101.99.18:12506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deargrampy.net"] [uri "/.git/config"] [unique_id "assFxWl_lyIrj4jnjAtPnQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-10 07:58:09
(1 day ago)
[10/Oct/2026:10:58:08 +0300] -- 141.101.99.18 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[10/Oct/2026:10:58:08 +0300] -- 141.101.99.18 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /index.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Cherryh4ck
2026-10-10 05:08:58
(1 day ago)
Blocked by UFW [2095/tcp] | SPT: 11190 | TTL: 55 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sef ...
show more
Blocked by UFW [2095/tcp] | SPT: 11190 | TTL: 55 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-10 04:17:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 00:16:56.504824 2026] [security2:error] [pid 14756:tid 14781] [client 141.101.99.18:11854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daviscountyossr.org"] [uri "/.env.dev"] [unique_id "asm8OOLe_GT7U9X_W1L74wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 21:49:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:49:39.756909 2026] [security2:error] [pid 1342:tid 1342] [client 141.101.99.18:9445] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cheaptrafficschool247.com"] [uri "/.git/HEAD"] [unique_id "aslhc1W6xbxxvUmYWQgKiwAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-09 11:54:12
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-10-09 11:05:59
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 13:20:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:20:03.047834 2026] [security2:error] [pid 1350:tid 1350] [client 141.101.99.18:13445] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.havilahmalone.com"] [uri "/.env.save"] [unique_id "aseYg92u44rhq7zTM5PzngAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-10-08 10:10:04
(3 days ago)
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 07:16:50
(3 days ago)
[08/Oct/2026:10:16:49 +0300] -- 141.101.99.18 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[08/Oct/2026:10:16:49 +0300] -- 141.101.99.18 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 07:07:05
(3 days ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.99.18 - - [08/Oct/2026:09:07:02 +0200] "GET /.env.staging HTTP/1.1" 301 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:58:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:58:14.660174 2026] [security2:error] [pid 21229:tid 21229] [client 141.101.99.18:12795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allseniorsolutions.com"] [uri "/.env.dev"] [unique_id "asc_BlIK-yrj88bI1MXy7gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack