πΊπΈ
TPI-Abuse
2026-10-10 13:38:33
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 09:38:26.356600 2026] [security2:error] [pid 21667:tid 21667] [client 141.101.99.6:12311] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||silalaw.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "silalaw.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "aso_0sy9OLwzA8mpHNaMJQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 01:44:37
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 21:44:34.172010 2026] [security2:error] [pid 20347:tid 20347] [client 141.101.99.6:12575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamestaylorart.com"] [uri "/.env.dev"] [unique_id "asmYguaUULJ5mVOJWe_J9wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
altenglaner
2026-10-09 13:55:02
(1 day ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 10:37:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 06:37:40.171767 2026] [security2:error] [pid 3886:tid 3886] [client 141.101.99.6:10170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ecuablue.farm"] [uri "/.env.local"] [unique_id "asjD9GsYko3bjaBq_U8tSwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 18:18:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:18:03.708786 2026] [security2:error] [pid 3590:tid 3590] [client 141.101.99.6:14277] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wendywonjungkim.com"] [uri "/.env"] [unique_id "asfeWxI6m00fnmp5CyKRYgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 17:10:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:10:25.233961 2026] [security2:error] [pid 11114:tid 11126] [client 141.101.99.6:13885] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "navinole.com"] [uri "/.git/HEAD"] [unique_id "asfOgX2qyENfRwCYmnOgQAAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 16:41:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:41:29.186362 2026] [security2:error] [pid 23227:tid 23227] [client 141.101.99.6:11778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.images4themind.com"] [uri "/.htaccess"] [unique_id "asfHuV_aMa4h6RtXnmx4_wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 14:47:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:47:10.768398 2026] [security2:error] [pid 30734:tid 30734] [client 141.101.99.6:11274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.marxistphilosophy.org"] [uri "/.env"] [unique_id "ases7raD8FkDZVaEaBIM6QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
louis77
2026-10-08 13:32:31
(2 days ago)
PHP application attack attempt - Path: /index.php.bak, Method: GET, UA: Mozilla/5.0 (X11; Linux x86_ ...
show more
PHP application attack attempt - Path: /index.php.bak, Method: GET, UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 11:56:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:56:00.698439 2026] [security2:error] [pid 17439:tid 17439] [client 141.101.99.6:12903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wsspy.com"] [uri "/wp-config.php.save"] [unique_id "aseE0HJZaKDrdOCj6WLL1gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 11:27:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:27:44.640454 2026] [security2:error] [pid 22494:tid 22685] [client 141.101.99.6:11219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nourishmentofthesoul.org"] [uri "/.env.local"] [unique_id "asd-MFs4afaBFQeONl0X5AAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-10-08 11:18:07
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 09:04:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:04:13.354259 2026] [security2:error] [pid 2601:tid 2601] [client 141.101.99.6:9410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sendvalentinecard.com"] [uri "/wp-config.php.old"] [unique_id "asdcjRjUB-15kctNqDA8IgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 08:10:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 04:10:53.282811 2026] [security2:error] [pid 16376:tid 16376] [client 141.101.99.6:12289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mainescentsecrets.com"] [uri "/wp-config.php.save"] [unique_id "asdQDfgnUtUrjTrFsufl8QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-10-07 21:42:39
(2 days ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 141.101.99.6 - - [07/Oct/2026:23:42:38 +0200] "GET /wp-config.php.old HTTP/1.1" 301 601 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack