๐บ๐ฆ
URAN Publishing Service
2026-10-10 00:43:11
(4 hours ago)
[10/Oct/2026:03:43:10 +0300] -- 141.101.99.20 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[10/Oct/2026:03:43:10 +0300] -- 141.101.99.20 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-09 16:28:24
(13 hours ago)
141.101.99.20 - - [09/Oct/2026:16:27:53 +0000] "GET /.env.local HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iP ...
show more
141.101.99.20 - - [09/Oct/2026:16:27:53 +0000] "GET /.env.local HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1" "2a06:98c0:3600::103" edge="141.101.99.20"
141.101.99.20 - - [09/Oct/2026:16:27:55 +0000] "GET /.terraform/terraform.tfstate.backup HTTP/2.0" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0" "2a06:98c0:3600::103" edge="141.101.99.20"
141.101.99.20 - - [09/Oct/2026:16:27:55 +0000] "GET /wp-config.php HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.1" "2a06:98c0:3600::103" edge="141.101.99.20"
141.101.99.20 - - [09/Oct/2026:16:27:56 +0000] "GET /wp-config.php.save HTTP/2.0" 403 0 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 06:37:51
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 02:37:47.608333 2026] [security2:error] [pid 4816:tid 4829] [client 141.101.99.20:13185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nourishmentofthesoul.org"] [uri "/wp-config.php.bak"] [unique_id "asiLu0kVUnUMkhd3jz72TAAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RamSet
2026-10-09 01:01:28
(1 day ago)
[ycr] HTTP-Probe on port 443 (via domain). 5 distinct paths probed in 3s. Sustained 5 req/min, 5 non ...
show more
[ycr] HTTP-Probe on port 443 (via domain). 5 distinct paths probed in 3s. Sustained 5 req/min, 5 nonexistent paths (404). Paths: /.env.save, /.npmrc, /.terraform/terraform.tfstate.backup, /appsettings.json, /config.yml
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 17:05:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:04:59.751413 2026] [security2:error] [pid 30606:tid 30606] [client 141.101.99.20:12465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "enlightened-workplace.com"] [uri "/.git/HEAD"] [unique_id "asfNO5ugJ5jl8tPZz4QgfAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Yosi
2026-10-08 14:38:48
(1 day ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-08 14:12:40
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:12:33.908465 2026] [security2:error] [pid 12563:tid 12563] [client 141.101.99.20:12868] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sunstrongmetal.com"] [uri "/.env.old"] [unique_id "asek0Yg2vGrXgkdHccGA1AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 13:20:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:20:07.137104 2026] [security2:error] [pid 1401:tid 1401] [client 141.101.99.20:10264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.havilahmalone.com"] [uri "/.htaccess"] [unique_id "aseYh6aFQwWotKWUxA4meQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-10-08 09:53:01
(1 day ago)
141.101.99.20 - - [08/Oct/2026:11:53:00 +0200] "GET /.env.backup HTTP/1.1" 302 467 "-" "Mozilla/5.0 ...
show more
141.101.99.20 - - [08/Oct/2026:11:53:00 +0200] "GET /.env.backup HTTP/1.1" 302 467 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 04:30:34
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-10-08 04:11:54
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:59:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:59:18.094827 2026] [security2:error] [pid 14898:tid 14949] [client 141.101.99.20:12259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foresthillseast.com"] [uri "/wp-config.php"] [unique_id "ascVFp8Yl_hjJhCBsM9EegAAAZE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:39:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:39:47.298292 2026] [security2:error] [pid 9958:tid 9958] [client 141.101.99.20:10250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vvs-inc.com"] [uri "/wp-config.php.bak"] [unique_id "asb0Y2F2T4_fVP2Oct8SGAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-08 00:44:11
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:39:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:39:29.838203 2026] [security2:error] [pid 24980:tid 24989] [client 141.101.99.20:13046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "retrieversocal.com"] [uri "/.git/config"] [unique_id "asbYMZvcDovX4AdXDPxNtwAAAYI"]
show less
Brute-Force
Bad Web Bot
Web App Attack