๐ฉ๐ช
webko.si
2026-09-30 17:28:36
(8 hours ago)
DKK: Bruteforce web app access, URI detail: '/.git/config'.
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-30 15:31:53
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:36:29
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:36:20.964160 2026] [security2:error] [pid 3196:tid 3196] [client 141.101.99.25:10013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.salinabible.org"] [uri "/.env"] [unique_id "arz0NMt2KuZNiF_pqQZk7QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:51:28
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:51:21.841233 2026] [security2:error] [pid 27986:tid 27986] [client 141.101.99.25:12790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "serranoscoffee.com"] [uri "/.env.staging"] [unique_id "arx5KRq9UXaxe7YDGx8uEgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:03:47
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:03:42.577201 2026] [security2:error] [pid 8415:tid 8415] [client 141.101.99.25:11184] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nationalnova.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nationalnova.com"] [uri "/index.php.bak"] [unique_id "arwZnn_yx65ime9K6aTzdQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:15:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:15:16.611526 2026] [security2:error] [pid 26575:tid 26575] [client 141.101.99.25:10385] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eagrant.com"] [uri "/.svn/entries"] [unique_id "arwORAqpViK-RZxSlmWV1AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-29 17:43:16
(1 day ago)
[29/Sep/2026:20:43:15 +0300] -- 141.101.99.25 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[29/Sep/2026:20:43:15 +0300] -- 141.101.99.25 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 14:48:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 10:48:33.914857 2026] [security2:error] [pid 30905:tid 30905] [client 141.101.99.25:10989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qed-consulting.co"] [uri "/.env"] [unique_id "arvPwT5Zk92DQcSsz8laTAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 13:31:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:31:31.157620 2026] [security2:error] [pid 28885:tid 28885] [client 141.101.99.25:14240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tremulant.com"] [uri "/.git/HEAD"] [unique_id "aru9sw91qEbFl3NLQhy1sAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 11:33:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 07:33:03.201558 2026] [security2:error] [pid 21215:tid 21215] [client 141.101.99.25:12908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spectorworld.com"] [uri "/.git/HEAD"] [unique_id "aruh7xX5JdG1Vvvz9iNPCQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-29 11:04:25
(1 day ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
copestack
2026-09-29 01:30:10
(2 days ago)
Honeypot hit on ov-4e5936 (fail2ban jail: nginx-compat)
Web App Attack
๐ซ๐ฎ
abdubhai
2026-09-29 01:12:52
(2 days ago)
141.101.99.25 - - [29/Sep/2026:0
...
Brute-Force
Anonymous
2026-09-28 15:52:10
(2 days ago)
apache vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 13:08:10
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 09:08:05.183948 2026] [security2:error] [pid 18541:tid 18541] [client 141.101.99.25:13984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vandermeerlab.org"] [uri "/.env.production"] [unique_id "arfDtbwvAJ4xJcyVl7trpwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack