๐บ๐ธ
TPI-Abuse
2026-10-10 17:29:03
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 13:28:58.435056 2026] [security2:error] [pid 9238:tid 9238] [client 104.23.223.164:9504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "towermedia.net"] [uri "/.git/config"] [unique_id "asp12tpPM9wRGiO_67IzsgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 17:05:00
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 13:04:55.642860 2026] [security2:error] [pid 32753:tid 32753] [client 104.23.223.164:12170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "the-schlosser.net"] [uri "/.git/config"] [unique_id "aspwN_Xb61iv4_iYLJdY1AAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 16:46:23
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 12:46:16.718042 2026] [security2:error] [pid 11450:tid 11450] [client 104.23.223.164:12528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swetzer.net"] [uri "/.git/config"] [unique_id "aspr2B_XpxwttjzyDknlogAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 16:28:47
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 12:28:41.190632 2026] [security2:error] [pid 14389:tid 14389] [client 104.23.223.164:12030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hal.dance"] [uri "/.git/config"] [unique_id "aspnuanJahgBlrZsUgm0NwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 15:50:10
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 11:50:03.048426 2026] [security2:error] [pid 23187:tid 23187] [client 104.23.223.164:11066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sexycyborg.net"] [uri "/.git/config"] [unique_id "aspeqwZZgl_4Rn_96oYeDwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 10:09:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 06:09:27.145946 2026] [security2:error] [pid 19878:tid 19881] [client 104.23.223.164:14209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gatheredandco.net"] [uri "/.git/config"] [unique_id "asoO11JYDux8a5dTNmEtdgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-10 08:58:42
(11 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
craudiovizai
2026-10-10 00:30:40
(19 hours ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php, /wp-admin/install.php?step=1. Blocked at the edge.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 10:17:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 06:17:47.650217 2026] [security2:error] [pid 32384:tid 32384] [client 104.23.223.164:10417] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimwilsonstudios.com"] [uri "/.git/config"] [unique_id "asi_S52JUTuBxDppPnBEKwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 07:43:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 03:43:54.055059 2026] [security2:error] [pid 31244:tid 31244] [client 104.23.223.164:9944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earlsworkshop.com"] [uri "/.git/config"] [unique_id "asibOpvPdFLd5NK3BM_0ywAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
craudiovizai
2026-10-09 06:30:48
(1 day ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /wp-admin/install.php?step=1. Blocked at the edge.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 05:46:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:46:09.717836 2026] [security2:error] [pid 3125:tid 3125] [client 104.23.223.164:11041] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asurprisinglittletown.com"] [uri "/.git/config"] [unique_id "ash_oTYCY9E8DLQImGYz-QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
craudiovizai
2026-10-07 18:30:39
(3 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐ณ๐ด
jad-abuse
2026-10-07 11:11:50
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐ง๐ช
voormedia
2026-10-07 05:59:39
(3 days ago)
Accessed trap at '/.git/config'
Web App Attack