๐บ๐ธ
mawan
2026-08-22 00:02:32
(23 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ง๐ช
voormedia
2026-08-18 01:32:42
(4 days ago)
Accessed trap at '/.git/HEAD'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:03:33
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:03:27.168753 2026] [security2:error] [pid 5813:tid 5813] [client 104.22.176.7:12995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.northcoastgolfden.com"] [uri "/.git/config"] [unique_id "aoLOX5aE7L6MRlg3BFdM4gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:18:38
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:18:33.199723 2026] [security2:error] [pid 27052:tid 27052] [client 104.22.176.7:10213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "summithost.com"] [uri "/.git/config"] [unique_id "aoLD2XJ_1sEHlpWv6bNrPQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:59:19
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:59:12.453630 2026] [security2:error] [pid 27299:tid 27319] [client 104.22.176.7:14301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.iacsb.com"] [uri "/.git/HEAD"] [unique_id "aoKxQC-RviMvqYKkLbtiYAAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-17 04:09:35
(5 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:27:18
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:27:10.428505 2026] [security2:error] [pid 25457:tid 25457] [client 104.22.176.7:9610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rharano.org"] [uri "/.git/config"] [unique_id "aoJ_jmH8aoS4xiIKh5GMVwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-17 03:15:41
(5 days ago)
[MonAug1705:15:38.8381012026][security2:error][pid1065777:tid1065797][client104.22.176.7:0]ModSecuri ...
show more
[MonAug1705:15:38.8381012026][security2:error][pid1065777:tid1065797][client104.22.176.7:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"aaaa6877.org\"][uri\"/.git/config\"][unique_id\"aoJ82o5Bjv2S4T5TbFOJxQAAANE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:49:12
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:49:06.396590 2026] [security2:error] [pid 16313:tid 16313] [client 104.22.176.7:10646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.falundafatr.org"] [uri "/.git/config"] [unique_id "aoJ2ou0-FmVYWc9nbDT2CgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 00:22:21
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 20:22:14.180794 2026] [security2:error] [pid 28702:tid 28702] [client 104.22.176.7:12172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.psychtraining.org"] [uri "/.git/config"] [unique_id "aoJUNrrO8boIgSGpDX7HsgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:22:35
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:22:30.035256 2026] [security2:error] [pid 20024:tid 20024] [client 104.22.176.7:10699] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.albrittonmcclain.com"] [uri "/.git/config"] [unique_id "aoFzRlel8iTdpUZcMvJkkQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 04:40:21
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.176.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:40:17.224414 2026] [security2:error] [pid 15389:tid 15389] [client 104.22.176.7:12043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.enriquejezik.com"] [uri "/.git/HEAD"] [unique_id "aoE_MT_KU8EYLwEWbvh84gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-16 03:30:02
(6 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-15 20:12:12
(1 week ago)
[15/Aug/2026:23:12:12 +0300] -- 104.22.176.7 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[15/Aug/2026:23:12:12 +0300] -- 104.22.176.7 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-15 04:20:25
(1 week ago)
Wordpress malicious attack:[octablocked]
Web App Attack