๐บ๐ธ
TPI-Abuse
2026-08-25 20:57:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 16:56:58.998328 2026] [security2:error] [pid 784:tid 784] [client 104.23.160.39:9473] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sfpantry.com"] [uri "/.git/config"] [unique_id "ao4Bmnog7b1TBnpaN4c3NwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 18:21:25
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 14:21:19.346417 2026] [security2:error] [pid 497:tid 497] [client 104.23.160.39:13383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.strippolefitness.com"] [uri "/.git/config"] [unique_id "ao3dH06L8Yv95jVR53bzwQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 16:42:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 12:42:54.790955 2026] [security2:error] [pid 10207:tid 10207] [client 104.23.160.39:10477] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.calicoinc.com"] [uri "/.git/config"] [unique_id "ao3GDuYo2GafHTV-BUpR9AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Little Iguana
2026-08-25 13:37:33
(11 hours ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ฉ๐ช
Lino Project
2026-08-25 09:44:17
(14 hours ago)
104.23.160.39 - - [25/Aug/2026:11:44:16 +0200] "GET /.git/HEAD HTTP/2.0" 403 253 "-" "Mozilla/5.0 (X ...
show more
104.23.160.39 - - [25/Aug/2026:11:44:16 +0200] "GET /.git/HEAD HTTP/2.0" 403 253 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 09:38:51
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:38:45.687606 2026] [security2:error] [pid 15031:tid 15207] [client 104.23.160.39:13567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.arizonasolutionsgroup.com"] [uri "/.git/HEAD"] [unique_id "ao1ipX5W_Ix_aygWW0_5mQAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 07:47:40
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:47:32.581417 2026] [security2:error] [pid 5350:tid 5350] [client 104.23.160.39:14324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jamroomrecording.com"] [uri "/.git/HEAD"] [unique_id "ao1IlPId3U0meBIdWZNN4gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 06:12:30
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 02:12:26.127188 2026] [security2:error] [pid 10857:tid 10857] [client 104.23.160.39:11868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cfabeachblvd.com"] [uri "/.git/config"] [unique_id "ao0ySsCcbhVncZ_cty51-gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 01:46:05
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 21:45:56.493322 2026] [security2:error] [pid 23471:tid 23471] [client 104.23.160.39:9895] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.skulldump.com"] [uri "/.git/HEAD"] [unique_id "aozz1N25u35F6WvpdH0o4wAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-24 22:03:57
(1 day ago)
cloudlinux2 fail2ban: 2026-08-24 23:58:59,274 fail2ban.actions [1464]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-24 23:58:59,274 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Ban 103.65.27.180cloudlinux2 fail2ban: 2026-08-24 23:58:59,280 fail2ban.filter [1464]: INFO [recidive] Found 103.65.27.180 - 2026-08-24 23:58:59cloudlinux2 fail2ban: 2026-08-24 23:58:58,775 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 103.65.27.180 - 2026-08-24 23:58:58cloudlinux2 fail2ban: 2026-08-24 23:59:23,925 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.160.39 - 2026-08-24 23:59:23cloudlinux2 fail2ban: 2026-08-24 23:59:23,936 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.160.101 - 2026-08-24 23:59:23cloudlinux2 fail2ban: 2026-08-24 23:59:43,404 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.82.229 - 2026-08-24 23:59:43cloudlinux2 fail2ban: 2026-08-24 23:59:41,571 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 195.63.19.53 - 2026-08-24 23:59:41cloudlinux2 fail2ban: 2026-08
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-24 22:01:40
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-24 20:47:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 16:47:14.060905 2026] [security2:error] [pid 27904:tid 27904] [client 104.23.160.39:11838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.diamondtrailerserv.com"] [uri "/.git/HEAD"] [unique_id "aoyt0t0TFijekpTlePyenwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 20:30:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 16:30:26.145351 2026] [security2:error] [pid 22743:tid 22743] [client 104.23.160.39:10743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "d-sinema.com"] [uri "/.git/config"] [unique_id "aoyp4o4q-myWYrdCX9MiCwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 19:22:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 15:22:06.050008 2026] [security2:error] [pid 30859:tid 30859] [client 104.23.160.39:13856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "batw.net"] [uri "/.git/HEAD"] [unique_id "aoyZ3loSdV8yDMAhc0anxQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 18:11:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 14:11:09.765279 2026] [security2:error] [pid 16215:tid 16215] [client 104.23.160.39:9375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.fritsknuf.com"] [uri "/.git/config"] [unique_id "aoyJPeaPuLJsDw_ieCX0xQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack