๐บ๐ธ
TPI-Abuse
2026-10-10 04:45:15
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 00:45:11.297126 2026] [security2:error] [pid 13805:tid 13805] [client 141.101.99.29:13213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcsteven.com"] [uri "/.env.backup"] [unique_id "asnC19iuVks4bQgQCmmexwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:36:20
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:36:16.422482 2026] [security2:error] [pid 19831:tid 19831] [client 141.101.99.29:14190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||poulsoncustomhomes.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "poulsoncustomhomes.com"] [uri "/index.php.bak"] [unique_id "aslQQHtq-8cvNAh9F2ziYwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 09:11:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 05:11:47.830635 2026] [security2:error] [pid 15401:tid 15401] [client 141.101.99.29:11543] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "corinthianscruise.org"] [uri "/wp-config.php.bak"] [unique_id "asiv04dJ7IkvEWIYWMnBWAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 00:12:26
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฌ๐ง
Yosi
2026-10-08 21:33:47
(1 day ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ฉ๐ช
altenglaner
2026-10-08 19:01:13
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 15:34:14
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 14:00:13
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:00:03.626528 2026] [security2:error] [pid 4954:tid 4954] [client 141.101.99.29:11800] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sunstrongmetal.com"] [uri "/.env.staging"] [unique_id "aseh41B7PGWlRo9JJJDhAgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-08 10:08:56
(2 days ago)
[08/Oct/2026:13:08:56 +0300] -- 141.101.99.29 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[08/Oct/2026:13:08:56 +0300] -- 141.101.99.29 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-10-08 09:53:02
(2 days ago)
141.101.99.29 - - [08/Oct/2026:11:53:00 +0200] "GET /.env.dev HTTP/1.1" 302 461 "-" "Mozilla/5.0 (Ma ...
show more
141.101.99.29 - - [08/Oct/2026:11:53:00 +0200] "GET /.env.dev HTTP/1.1" 302 461 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-08 08:44:38
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:43:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:42:49.779979 2026] [security2:error] [pid 31496:tid 31496] [client 141.101.99.29:13915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achari.com"] [uri "/.env.production"] [unique_id "asc7aSoP4p9pT08oJn6OEgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:10:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:09:54.289276 2026] [security2:error] [pid 23458:tid 23458] [client 141.101.99.29:11396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reciprodyne.com"] [uri "/.env.local"] [unique_id "asczshNkAJ0lQ0ukvn8WXgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-08 05:16:24
(2 days ago)
3 attacks on env grabbing URLs, password/key grabbing URLs:
GET /.env.save HTTP/1.1
GET /.ssh/id_ed2 ...
show more
3 attacks on env grabbing URLs, password/key grabbing URLs:
GET /.env.save HTTP/1.1
GET /.ssh/id_ed25519 HTTP/1.1
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 04:47:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:47:18.780485 2026] [security2:error] [pid 19924:tid 19924] [client 141.101.99.29:13735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toxicwater.com"] [uri "/.env.backup"] [unique_id "ascgVv-46qW1nl_czhq2ugAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack