πΊπΈ
TPI-Abuse
2026-10-07 10:53:00
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:52:53.250044 2026] [security2:error] [pid 2761:tid 2761] [client 141.101.99.218:14103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.voodooshop.com"] [uri "/.env.staging"] [unique_id "asYkheTKYRg4mbpGEu7QfAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 07:33:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 03:33:36.042456 2026] [security2:error] [pid 21574:tid 21574] [client 141.101.99.218:10827] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fancycleaners.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fancycleaners.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asX10G14SHPBncCe3O6bNAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 05:44:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:44:49.597628 2026] [security2:error] [pid 11627:tid 11680] [client 141.101.99.218:13026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotairwelder.com"] [uri "/wp-config.php.bak"] [unique_id "asXcUU6dypXn9DIvTU7wnQAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 16:38:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:38:36.320986 2026] [security2:error] [pid 9507:tid 9507] [client 141.101.99.218:12565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toytractorrepair.com"] [uri "/.htaccess"] [unique_id "asUkDJ3v62F1IrJrDaMnxQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 12:28:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:28:03.619037 2026] [security2:error] [pid 29257:tid 29257] [client 141.101.99.218:13893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hendersonhomes.com"] [uri "/.env.old"] [unique_id "asTpU0lkJ1u5bqB1ffG68QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 07:43:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:43:22.489735 2026] [security2:error] [pid 20470:tid 20470] [client 141.101.99.218:12827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "new-bethel-baptist-church.com"] [uri "/.git/HEAD"] [unique_id "asSmmiIgDhAhbdbUv8rNZgAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 04:34:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 00:34:15.961682 2026] [security2:error] [pid 8239:tid 8261] [client 141.101.99.218:9378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captainpurpleproductions.com"] [uri "/.env.bak"] [unique_id "asR6R5wVFJ625sBjNiboHAAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 04:54:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:53:54.263182 2026] [security2:error] [pid 3446:tid 3446] [client 141.101.99.218:13870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaleidoscope-glass.com"] [uri "/.env.bak"] [unique_id "asMtYkuoP3Oirk7ZCLn-YAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Lee Daniel
2026-09-29 06:58:25
(1 week ago)
141.101.99.218 - - [29/Sep/2026:02:58:25 -0400] "GET /.aws/credentials HTTP/1.1" 403 344 "-" "Mozill ...
show more
141.101.99.218 - - [29/Sep/2026:02:58:25 -0400] "GET /.aws/credentials HTTP/1.1" 403 344 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-09-29 06:32:13
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 21:52:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 17:52:28.579476 2026] [security2:error] [pid 17840:tid 17840] [client 141.101.99.218:10455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "khaoula.com"] [uri "/.git/HEAD"] [unique_id "arrhnE7Q-nlD1GdYSReUSwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 15:07:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 11:06:52.747726 2026] [security2:error] [pid 1437:tid 1437] [client 141.101.99.218:13744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaleidoscope-glass.com"] [uri "/.git/HEAD"] [unique_id "arqCjDEOQdw4lId3OkofhgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-26 10:48:14
(1 week ago)
[26/Sep/2026:13:48:13 +0300] -- 141.101.99.218 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[26/Sep/2026:13:48:13 +0300] -- 141.101.99.218 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
π§π¬
Stoyko Stoykov
2026-09-24 20:22:44
(1 week ago)
141.101.99.218 - - [24/Sep/2026:23:22:44 +0300] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gr ...
show more
141.101.99.218 - - [24/Sep/2026:23:22:44 +0300] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-connections HTTP/2.0" 404 114 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:121.0) Gecko/20100101 Firefox/121.0"
...
show less
Hacking
Web App Attack
π§π¬
Stoyko Stoykov
2026-09-23 10:58:31
(2 weeks ago)
141.101.99.218 - - [23/Sep/2026:13:58:30 +0300] "POST /wordpress/wordpress/wp-json/batch/v1 HTTP/2.0 ...
show more
141.101.99.218 - - [23/Sep/2026:13:58:30 +0300] "POST /wordpress/wordpress/wp-json/batch/v1 HTTP/2.0" 404 176 "https://mail.it-systems.org/wordpress/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack