๐บ๐ธ
TPI-Abuse
2026-10-07 10:19:51
(30 minutes ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:19:46.673741 2026] [security2:error] [pid 17225:tid 17228] [client 141.101.99.74:14160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "volcano-sa.com"] [uri "/.env.production"] [unique_id "asYcwhCwnhyoNeBEe6eKXQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 03:59:04
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:58:35.955224 2026] [security2:error] [pid 27473:tid 27473] [client 141.101.99.74:12241] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mountainjaytherapy.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mountainjaytherapy.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asXDa8ihoAYFRIoSFYckJAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-07 03:15:16
(7 hours ago)
[WedOct0705:15:03.7601082026][security2:error][pid3282853:tid3282878][client141.101.99.74:0]ModSecur ...
show more
[WedOct0705:15:03.7601082026][security2:error][pid3282853:tid3282878][client141.101.99.74:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"4hosts.net\"][uri\"/.netrc\"][unique_id\"asW5N81v_e3M0Lp_INV-3QAAANc\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:37:39
(11 hours ago)
(mod_security) mod_security (id:949110) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:37:36.371566 2026] [security2:error] [pid 951:tid 951] [client 141.101.99.74:11753] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/%2eenv"] [unique_id "asWGQM_CSViYv1mCTIQ7LQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 22:55:35
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 18:55:28.226021 2026] [security2:error] [pid 2920:tid 2933] [client 141.101.99.74:10581] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertagmetairie.com"] [uri "/.env.local"] [unique_id "asV8YB2H9gtiNq1eNHI2eAAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-10-06 21:06:29
(13 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:07:07
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:06:58.768284 2026] [security2:error] [pid 15413:tid 15413] [client 141.101.99.74:13880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "microscope.modelengines.info"] [uri "/.env.old"] [unique_id "asUcoigxpt6a4arZsPnx-wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:32:28
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:32:21.795571 2026] [security2:error] [pid 1576:tid 1576] [client 141.101.99.74:13796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vittariacapital.com"] [uri "/.git/HEAD"] [unique_id "asUUhb7wBkDABTbqj-KP2QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-06 14:39:09
(20 hours ago)
[06/Oct/2026:17:39:07 +0300] -- 141.101.99.74 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[06/Oct/2026:17:39:07 +0300] -- 141.101.99.74 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:27:32
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:27:25.830841 2026] [security2:error] [pid 28376:tid 28376] [client 141.101.99.74:9766] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||xtcdesigns.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "xtcdesigns.com"] [uri "/index.php.bak"] [unique_id "asSi3WZkxkDxx4wbPYv27QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 04:39:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 00:38:58.671462 2026] [security2:error] [pid 6892:tid 6892] [client 141.101.99.74:10129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title30.com"] [uri "/.env.production"] [unique_id "asR7YnXiXCR9oWYilSfnRgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 23:46:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 19:46:05.235244 2026] [security2:error] [pid 32424:tid 32424] [client 141.101.99.74:12620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tribalpacifica.com"] [uri "/.env.staging"] [unique_id "asQ2vVXZhQ7ZVgb1ta8UoQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 21:37:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:37:07.732072 2026] [security2:error] [pid 4365:tid 4365] [client 141.101.99.74:13393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "new-bethel-baptist-church.com"] [uri "/.env.save"] [unique_id "asQYgwpUNOMxPdmy1u7DWwAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2026-10-05 06:21:22
(2 days ago)
Suspicious malicious activity
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-10-01 05:22:21
(6 days ago)
[01/Oct/2026:08:22:21 +0300] -- 141.101.99.74 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[01/Oct/2026:08:22:21 +0300] -- 141.101.99.74 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack