π³π±
homeshowdomain.nl
2026-08-24 22:00:31
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-24
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-24 14:11:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 10:10:58.479894 2026] [security2:error] [pid 2989:tid 3049] [client 104.23.160.27:12820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gilesrentalcars.com"] [uri "/.git/config"] [unique_id "aoxQ8hRKTLH02R6pghplcgAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 13:18:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:18:40.143503 2026] [security2:error] [pid 4075:tid 4075] [client 104.23.160.27:10623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elderlyassociation.org"] [uri "/.git/HEAD"] [unique_id "aoxEsCLzW0M3h1zDYqSzbQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 12:12:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 08:12:22.648407 2026] [security2:error] [pid 25756:tid 25769] [client 104.23.160.27:10394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.northernindianaatheists.com"] [uri "/.git/HEAD"] [unique_id "aow1Jjv5CLKG7xOqdePeywAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-08-22 19:36:35
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π¦πΊ
paulshipley.com.au
2026-08-22 09:00:14
(4 days ago)
[Sat Aug 22 19:00:13.235871 2026] [security2:error] [pid 264810] [client 104.23.160.27:10115] [clien ...
show more
[Sat Aug 22 19:00:13.235871 2026] [security2:error] [pid 264810] [client 104.23.160.27:10115] [client 104.23.160.27] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/.git/config"] [unique_id "aollHb1SVkIPzmFRHT9ypgAAAAc"]
...
show less
Web App Attack
π¬π§
openstrike.co.uk
2026-08-22 05:15:43
(4 days ago)
2 attacks on VC URLs:
GET /.git/HEAD HTTP/1.1
Hacking
πΊπΈ
TPI-Abuse
2026-08-20 15:03:25
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 11:03:17.013519 2026] [security2:error] [pid 15960:tid 15960] [client 104.23.160.27:12019] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thedreamcatchers.eu"] [uri "/.git/config"] [unique_id "aocXNZHXUXXN9MBZoAARRQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
voormedia
2026-08-20 09:26:01
(6 days ago)
Accessed trap at '/.git/config'
Web App Attack
π³π΄
jad-abuse
2026-08-20 06:46:34
(6 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 03:17:17
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 23:17:12.654672 2026] [security2:error] [pid 8881:tid 8881] [client 104.23.160.27:13369] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fiestadj.com.mx"] [uri "/.git/config"] [unique_id "aoZxuBoExsmoIA4JQFKe0wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 02:45:55
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 22:45:46.590858 2026] [security2:error] [pid 14553:tid 14553] [client 104.23.160.27:10978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jmms.mx"] [uri "/.git/config"] [unique_id "aoZqWvWYhg79_vcXfjMtzgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 00:56:01
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:55:56.290325 2026] [security2:error] [pid 7740:tid 7765] [client 104.23.160.27:9620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.1shot.us"] [uri "/.git/config"] [unique_id "aoZQnE4Dc0ImzBkHybINhAAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 00:16:44
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:16:21.652388 2026] [security2:error] [pid 27948:tid 27954] [client 104.23.160.27:12596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "classactionlawsuit.org.aafm.us"] [uri "/.git/HEAD"] [unique_id "aoZHVbsVzcYke7HPEhmWeAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-19 17:46:49
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 13:46:42.298500 2026] [security2:error] [pid 14141:tid 14141] [client 104.23.160.27:13123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.intra.es"] [uri "/.git/HEAD"] [unique_id "aoXsAgz5twbDLEuH-hKTbgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack