๐บ๐ธ
TPI-Abuse
2026-10-07 04:31:58
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:31:52.548174 2026] [security2:error] [pid 5844:tid 5844] [client 141.101.99.221:13267] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fancycleaners.com"] [uri "/.htaccess"] [unique_id "asXLOGYhaQ4Vxw1tlXGPtAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 04:13:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 00:12:54.366565 2026] [security2:error] [pid 19821:tid 19821] [client 141.101.99.221:12080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horsesaw.com"] [uri "/.env.staging"] [unique_id "asR1RsgpyzGkew1UxFZVgwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 03:29:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 23:29:44.436599 2026] [security2:error] [pid 7380:tid 7380] [client 141.101.99.221:10266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtrl.com"] [uri "/.env"] [unique_id "asRrKGjc_Iw9EuKqBeO5UgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 03:03:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 23:03:09.187895 2026] [security2:error] [pid 17509:tid 17509] [client 141.101.99.221:11538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.achildsspace.com"] [uri "/wp-config.php.old"] [unique_id "asRk7f_nq-GyIWAqjwtz4gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-05 22:35:27
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-10-05 04:09:04
(2 days ago)
vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 23:40:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:40:13.280640 2026] [security2:error] [pid 3453504:tid 3453522] [client 141.101.99.221:12533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sailcleaner.com"] [uri "/.env.save"] [unique_id "asLj3eCjOdp5jQmXSfdEXQAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 06:21:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 02:21:16.181543 2026] [security2:error] [pid 20878:tid 20878] [client 141.101.99.221:12070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehomemailbox.com"] [uri "/.env.backup"] [unique_id "asHwXBZmlWbfUYo1PjUj5wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
Erpelstolz
2026-10-01 16:07:49
(5 days ago)
fail2ban on bvseq; jail=cobi-wp
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:37:10
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:37:07.128310 2026] [security2:error] [pid 27296:tid 27296] [client 141.101.99.221:14097] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gapanda.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gapanda.com"] [uri "/index.php.bak"] [unique_id "ar2rM_vUiI4ryxVic-ixcAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 22:15:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:15:39.096345 2026] [security2:error] [pid 14139:tid 14139] [client 141.101.99.221:13641] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agingworkforcenews.com"] [uri "/.git/config"] [unique_id "arw4iz9gvnQFVm9snhPyOAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 00:19:42
(1 week ago)
[29/Sep/2026:03:19:42 +0300] -- 141.101.99.221 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp- ...
show more
[29/Sep/2026:03:19:42 +0300] -- 141.101.99.221 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/plugins/woocommerce/readme.txt HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-09-24 18:35:50
(1 week ago)
141.101.99.221 - - [24/Sep/2026:21:35:50 +0300] "GET /_profiler/phpinfo HTTP/2.0" 404 134 "-" "Mozil ...
show more
141.101.99.221 - - [24/Sep/2026:21:35:50 +0300] "GET /_profiler/phpinfo HTTP/2.0" 404 134 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ง๐ช
madeit
2026-09-18 16:58:08
(2 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-09-08 02:31:05
(4 weeks ago)
Web App Attack