๐บ๐ธ
TPI-Abuse
2026-08-27 22:41:43
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:41:37.617149 2026] [security2:error] [pid 24443:tid 24443] [client 104.23.160.200:9478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nysasports.com"] [uri "/.git/config"] [unique_id "apC9IW6dgYP2XIwSAuOAfgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:00:00
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:59:56.860759 2026] [security2:error] [pid 27999:tid 27999] [client 104.23.160.200:13540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.newcastle91.org"] [uri "/.git/config"] [unique_id "apBtDHKCCKZcPWsCTy6thgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-08-27 16:58:57
(16 hours ago)
Probing for .git:
104.23.160.200 - - [27/Aug/2026:14:12:52 +0200] "GET /.git/config HTTP/2.0" 403 54 ...
show more
Probing for .git:
104.23.160.200 - - [27/Aug/2026:14:12:52 +0200] "GET /.git/config HTTP/2.0" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 14:52:43
(18 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
4server
2026-08-27 13:03:03
(20 hours ago)
[ThuAug2715:02:59.3683822026][security2:error][pid1216470:tid1216530][client104.23.160.200:0]ModSecu ...
show more
[ThuAug2715:02:59.3683822026][security2:error][pid1216470:tid1216530][client104.23.160.200:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.martinairsagl.ch\"][uri\"/.git/HEAD\"][unique_id\"apA1g3uQXpk1l2qPoQ37nQAAAFM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 10:57:20
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:57:16.391381 2026] [security2:error] [pid 21601:tid 21601] [client 104.23.160.200:10725] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.disenowebprofesional.com"] [uri "/.git/HEAD"] [unique_id "apAYDPsPX11j3_DxtNHbTwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 09:30:28
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:30:21.894697 2026] [security2:error] [pid 23600:tid 23600] [client 104.23.160.200:10536] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.donations.freedrm.org"] [uri "/.git/config"] [unique_id "apADrf4Otr_r8ZkCJ9wUbQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-26 21:59:40
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 104.23.160.200 (US/United States/-) ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 104.23.160.200 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 19:28:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:28:09.697670 2026] [security2:error] [pid 10172:tid 10172] [client 104.23.160.200:11270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.elderlyassociation.org"] [uri "/.git/config"] [unique_id "ao8-SYougkL5dYvb_VJrHQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:15:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:15:42.506241 2026] [security2:error] [pid 3567:tid 3567] [client 104.23.160.200:12387] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.margroberts.com"] [uri "/.git/HEAD"] [unique_id "ao8tTiAoSRNb7dryFm67zAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 16:16:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:16:04.306042 2026] [security2:error] [pid 19867:tid 19867] [client 104.23.160.200:12184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adventiststoday.com"] [uri "/.git/config"] [unique_id "ao8RRFNyn17BjrzyFhqLJwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 11:23:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:23:01.189158 2026] [security2:error] [pid 10015:tid 10015] [client 104.23.160.200:12380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.haddadpharmacy.com"] [uri "/.git/HEAD"] [unique_id "ao7MlfQ_46u2iVP0H5Gx1wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 05:05:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:05:54.536079 2026] [security2:error] [pid 5916:tid 5916] [client 104.23.160.200:13734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "app.s1global.net.s1global.net"] [uri "/.git/config"] [unique_id "ao50MpiH6Cdv2yENLnB7dQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 22:25:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 18:25:43.214156 2026] [security2:error] [pid 6087:tid 6087] [client 104.23.160.200:12617] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.chicagowca.com"] [uri "/.git/config"] [unique_id "ao4WZ7AwjrglGfQzDTyBAAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 20:13:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 16:13:01.464511 2026] [security2:error] [pid 4768:tid 4768] [client 104.23.160.200:14222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nashuacubscouts.com.nashuaboyscouts.org"] [uri "/.git/HEAD"] [unique_id "ao33TXHYb6bLRJ4URF4eDwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack