๐ฏ๐ต
S.O.B.A. Dev.
2026-09-23 12:05:54
(1 day ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-09-05 22:00:43
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-09-05
Web App Attack
SSH
Hacking
๐ง๐ช
madeit
2026-09-01 23:27:30
(3 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 02:28:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 22:27:59.217678 2026] [security2:error] [pid 22376:tid 22376] [client 104.22.100.92:12673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "67ronin.com"] [uri "/.git/HEAD"] [unique_id "aoPDLwy6KXHnLMaGav2VigAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 23:11:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:11:02.598714 2026] [security2:error] [pid 12777:tid 12777] [client 104.22.100.92:10751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.brazilianbottom.com"] [uri "/.git/HEAD"] [unique_id "aoOVBhxi-OZf4HdU2qGmQQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 10:37:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:37:32.003163 2026] [security2:error] [pid 32652:tid 32761] [client 104.22.100.92:12115] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dermatologyneworleans.com.aafm.us"] [uri "/.git/config"] [unique_id "aoLkbDyN40k1TlUaM4kMJAAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:34:27
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:34:22.985835 2026] [security2:error] [pid 1758:tid 1795] [client 104.22.100.92:12919] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ahrgroup.com"] [uri "/.git/HEAD"] [unique_id "aoK5fsbHfhT1DYlLVDvKrQAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:30:30
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:30:24.624441 2026] [security2:error] [pid 22838:tid 22838] [client 104.22.100.92:12151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ubuciko.michaelthompson.biz"] [uri "/.git/config"] [unique_id "aoKqgA_WUb03D_86m0UuPQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:44:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:44:29.123955 2026] [security2:error] [pid 11143:tid 11279] [client 104.22.100.92:9636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "7sons.net"] [uri "/.git/config"] [unique_id "aoF4bf8ATxJDzEjY3JnSSgAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:02:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:02:25.420664 2026] [security2:error] [pid 2130241:tid 2130241] [client 104.22.100.92:9997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.register-yacht-belize.com"] [uri "/.git/config"] [unique_id "aoFScUk0Qi8RapWzBSC1nwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 02:01:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 22:01:02.909140 2026] [security2:error] [pid 3475:tid 3475] [client 104.22.100.92:12920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.travel-pix.com"] [uri "/.git/HEAD"] [unique_id "aoEZ3pOi9AJxZZ8dMKEiyQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 00:43:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 20:43:39.979295 2026] [security2:error] [pid 20795:tid 20795] [client 104.22.100.92:10262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinareemagazine.com"] [uri "/.git/HEAD"] [unique_id "aoEHu8UgZTd62b8gT27q3wAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-08-15 04:56:51
(1 month ago)
15/Aug/2026:06:56:50.559924 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
15/Aug/2026:06:56:50.559924 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.22.100.92] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at ARGS_NAMES:php echo esc_url( admin_url( 'images/freedom-4.svg?ver. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution: Direct Unix Command Execution"] [data "Matched Data: php found within ARGS_NAMES:php
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 19:21:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 15:21:33.765556 2026] [security2:error] [pid 14501:tid 14501] [client 104.22.100.92:12170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rockinr.org"] [uri "/.git/config"] [unique_id "an9qvcM-xPhGC0Nr8JVmjgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-13 11:55:02
(1 month ago)
suspicious request in access.log
Web App Attack