๐บ๐ธ
TPI-Abuse
2026-10-07 23:42:19
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:42:12.741271 2026] [security2:error] [pid 9117:tid 9117] [client 141.101.99.80:11147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "georgetownca.com"] [uri "/.env.bak"] [unique_id "asbY1HXLYw00zOr0cYFq0gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:00:25
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:00:06.658708 2026] [security2:error] [pid 8347:tid 8347] [client 141.101.99.80:9359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "majersigns.com"] [uri "/.env.dev"] [unique_id "asbO9hou5uBNPaUqGmXSYgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 22:17:07
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 18:16:57.637596 2026] [security2:error] [pid 15287:tid 15287] [client 141.101.99.80:13492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grupo-visalud.com"] [uri "/.env.backup"] [unique_id "asbE2dZjQv6-uGRihP8FLQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-10-07 21:10:24
(6 hours ago)
141.101.99.80 - - [07/Oct/2026:23:10:24 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ...
show more
141.101.99.80 - - [07/Oct/2026:23:10:24 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 20:37:23
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:37:19.380195 2026] [security2:error] [pid 19491:tid 19520] [client 141.101.99.80:10797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedprojectmanager.net"] [uri "/.env.save"] [unique_id "asatf_I-xk4TayT1H1IYbQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-07 20:26:00
(7 hours ago)
[WedOct0722:25:52.3710252026][security2:error][pid742:tid752][client141.101.99.80:0]ModSecurity:Acce ...
show more
[WedOct0722:25:52.3710252026][security2:error][pid742:tid752][client141.101.99.80:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"[a-z0-9]~\$\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1158\"][id\"390581\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-DataLeakage-attempttoaccessbackupfile\(disablethisruleifyourequireaccesstofilesthatendwithatilde\)\"][severity\"CRITICAL\"][hostname\"4hosts.net\"][uri\"/index.php~\"][unique_id\"asaq0FnTWOqAwRjdTB25jgAAAEU\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 14:57:35
(13 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 10:51:49
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 06:51:45.026716 2026] [security2:error] [pid 11521:tid 11521] [client 141.101.99.80:11854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pseudospace.com"] [uri "/.git/config"] [unique_id "asYkQaUj8uEspxb0AoRa2gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 05:18:49
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 01:18:33.842883 2026] [security2:error] [pid 29745:tid 29745] [client 141.101.99.80:12081] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffautry.com"] [uri "/wp-config.php.bak"] [unique_id "asXWKSZN0pALa1KH52OoAQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-10-07 05:13:31
(22 hours ago)
[07/Oct/2026:08:13:31 +0300] -- 141.101.99.80 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[07/Oct/2026:08:13:31 +0300] -- 141.101.99.80 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.production HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:26:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:26:02.115860 2026] [security2:error] [pid 18890:tid 18890] [client 141.101.99.80:14226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.diamondtrailerserv.com"] [uri "/.env.production"] [unique_id "asT26q8kkI9l2UmbOmtYDQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:48:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:48:08.704041 2026] [security2:error] [pid 23219:tid 23219] [client 141.101.99.80:10947] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redlandssprinkler.com"] [uri "/wp-config.php.old"] [unique_id "asTuCHZDuivf8b65dtVJrgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:59:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:59:39.651083 2026] [security2:error] [pid 7778:tid 7778] [client 141.101.99.80:11485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peregrineproject.com"] [uri "/.git/HEAD"] [unique_id "asTiq9EOC76SwbenjPCzJwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 05:47:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.99.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 01:46:37.918623 2026] [security2:error] [pid 23015:tid 23015] [client 141.101.99.80:13402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "terryhildebrandprints.com"] [uri "/.svn/entries"] [unique_id "asSLPVfaYPq-3rg8hkDsSQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-05 07:06:10
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack