π©πͺ
FeG Deutschland
2026-08-26 10:38:44
(12 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 10:05:40
(45 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:05:33.548458 2026] [security2:error] [pid 23368:tid 23368] [client 104.23.160.64:10674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cityoffoley.gov"] [uri "/.git/config"] [unique_id "ao66bRTG5UoekIv5iNUd1QAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 05:01:21
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:01:14.081485 2026] [security2:error] [pid 14901:tid 14901] [client 104.23.160.64:12471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rejuvenationresources.com"] [uri "/.git/config"] [unique_id "ao5zGqsRfd2xIc91B6Ph7AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 20:46:24
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 16:46:20.596892 2026] [security2:error] [pid 24407:tid 24407] [client 104.23.160.64:13687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.austintrauma.com"] [uri "/.git/config"] [unique_id "ao3_HNBh8_XVJ-vhNXPvGQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Blexyel
2026-08-25 06:26:04
(1 day ago)
104.23.160.64 - - [25/Aug/2026:08:26:03 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ...
show more
104.23.160.64 - - [25/Aug/2026:08:26:03 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 06:21:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 02:21:23.868275 2026] [security2:error] [pid 32003:tid 32003] [client 104.23.160.64:12163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rockymtnfire.com"] [uri "/.git/HEAD"] [unique_id "ao00Y9rXLoJJYnSwFhgQ9QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 05:32:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 01:32:22.724685 2026] [security2:error] [pid 24503:tid 24503] [client 104.23.160.64:9901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dpcreamery.com"] [uri "/.git/HEAD"] [unique_id "ao0o5hzmQgmy6kawVKXTJgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 02:19:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 22:19:25.733227 2026] [security2:error] [pid 15382:tid 15382] [client 104.23.160.64:11998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vccemail.net"] [uri "/.git/HEAD"] [unique_id "aoz7raWk5rHjQ1dYXnA_ZgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 01:25:17
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 21:25:09.558423 2026] [security2:error] [pid 18663:tid 18663] [client 104.23.160.64:12910] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dcagroup.armstrongenvironmental.com"] [uri "/.git/config"] [unique_id "aozu9e3Wi1kQEzrXW_lNVQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 23:42:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 19:42:10.247978 2026] [security2:error] [pid 16478:tid 16478] [client 104.23.160.64:11592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bookguardian.net"] [uri "/.git/config"] [unique_id "aozW0l7pIL0PiykezC3vqgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-24 21:59:51
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-24
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-24 21:21:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 17:21:48.691568 2026] [security2:error] [pid 7229:tid 7229] [client 104.23.160.64:12530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.interforce.com"] [uri "/.git/HEAD"] [unique_id "aoy17JPnWnttIY-T0iWyrwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
el-brujo
2026-08-24 21:15:28
(1 day ago)
24/Aug/2026:23:15:27.274920 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
24/Aug/2026:23:15:27.274920 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 104.23.160.64] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "quads.ddns.net"] [uri "/.git/config"] [unique_id "aoy0bxYQ8N3Ej9BLAl8smQAYt3Q"]
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 16:08:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 12:08:28.812593 2026] [security2:error] [pid 24857:tid 24857] [client 104.23.160.64:9403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bzbdesigns.com"] [uri "/.git/config"] [unique_id "aoxsfAPEZA_lgSAumI6WmwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 14:36:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 10:35:57.820251 2026] [security2:error] [pid 25918:tid 25918] [client 104.23.160.64:10254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.memelearning.net"] [uri "/.git/config"] [unique_id "aoxWzTJQQDiWcvcAsmY4AQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack