๐บ๐ธ
TPI-Abuse
2026-08-18 04:15:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 00:15:49.425479 2026] [security2:error] [pid 10445:tid 10445] [client 104.22.104.209:13239] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thalos.com.pe"] [uri "/.git/HEAD"] [unique_id "aoPcdbL9V8kQRitMXD4MqQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 00:10:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 20:10:32.673671 2026] [security2:error] [pid 12615:tid 12615] [client 104.22.104.209:11594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.zodiacgate.com"] [uri "/.git/config"] [unique_id "aoOi-N58J__TXXLJyW7WugAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 23:17:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:17:23.816933 2026] [security2:error] [pid 7083:tid 7083] [client 104.22.104.209:13198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.penjoki.us"] [uri "/.git/config"] [unique_id "aoOWgygfkywjxM9-ADMAMgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 10:46:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:46:30.730203 2026] [security2:error] [pid 11697:tid 11697] [client 104.22.104.209:9247] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.trevthomas.com"] [uri "/.git/config"] [unique_id "aoLmhnKLOflRxmMgIxb1xQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:04:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:04:14.859984 2026] [security2:error] [pid 1778:tid 1778] [client 104.22.104.209:9344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lajoze.com"] [uri "/.git/config"] [unique_id "aoLAfoF_wCIZ-Ar3mAwhBQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:37:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:37:44.590909 2026] [security2:error] [pid 21785:tid 21785] [client 104.22.104.209:13043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.creationorevolution.net"] [uri "/.git/HEAD"] [unique_id "aoKsOCVdDvnNMKS6MRYm_QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:27:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:27:20.773876 2026] [security2:error] [pid 18903:tid 18908] [client 104.22.104.209:12016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.newsrank.us"] [uri "/.git/HEAD"] [unique_id "aoKbuKNdGk2ks-lWdhOzzwAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 04:34:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:34:53.596540 2026] [security2:error] [pid 18919:tid 18919] [client 104.22.104.209:13204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "publications.flyingdodostudio.com"] [uri "/.git/HEAD"] [unique_id "aoKPbXwJ5YUaq0tJaGUGogAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-16 21:59:37
(1 week ago)
Auto-ban: >3000 req/min op 2026-08-16
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-16 05:30:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:30:20.951795 2026] [security2:error] [pid 24909:tid 24909] [client 104.22.104.209:10167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.w1rq.com"] [uri "/.git/HEAD"] [unique_id "aoFK7BG0Gd9GFIEt3oq3LAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 02:51:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 22:51:34.308790 2026] [security2:error] [pid 21586:tid 21586] [client 104.22.104.209:13169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.aquatreat.net"] [uri "/.git/config"] [unique_id "aoEltpWzA-rTOJA5PRYctgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 09:11:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 05:11:46.505050 2026] [security2:error] [pid 2071238:tid 2071250] [client 104.22.104.209:13784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfinancialmanager.org"] [uri "/.git/config"] [unique_id "aoAtUkOTEOSkD01VkXM52gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 05:35:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.104.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 01:35:28.828053 2026] [security2:error] [pid 20626:tid 20626] [client 104.22.104.209:10274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joepeters.org"] [uri "/.git/HEAD"] [unique_id "an6pICYCcZXpxkRY_nWBAgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HERA - Operations
2026-08-14 04:14:05
(1 week ago)
herrmann - searching for vulnerable scripts: HEAD 2026/08/14 06:14:05
Web App Attack
๐ฉ๐ช
4server
2026-08-13 00:09:27
(1 week ago)
[ThuAug1302:09:24.5731392026][security2:error][pid4168946:tid4168960][client104.22.104.209:0]ModSecu ...
show more
[ThuAug1302:09:24.5731392026][security2:error][pid4168946:tid4168960][client104.22.104.209:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"newbeauty-pully.ch\"][uri\"/.git/config\"][unique_id\"an0LNLvv9jHu4l6t3trp8QAAAIs\"]
show less
Port Scan
Brute-Force
Web App Attack