Anonymous
2026-09-13 16:36:17
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:06:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:06:34.692728 2026] [security2:error] [pid 13854:tid 13854] [client 104.23.225.125:10718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theblindmantylertx.com"] [uri "/.git/HEAD"] [unique_id "apZraggQMYNGpfgvkDiscwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-31 07:52:14
(2 weeks ago)
[31/Aug/2026:10:52:14 +0300] -- 104.23.225.125 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[31/Aug/2026:10:52:14 +0300] -- 104.23.225.125 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 22:28:10
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 18:28:01.656106 2026] [security2:error] [pid 17549:tid 17549] [client 104.23.225.125:10468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kelticdreamsranch.com"] [uri "/.git/HEAD"] [unique_id "apSucWXQXjqQGQACh7Yz4AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 01:36:13
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 21:36:08.602919 2026] [security2:error] [pid 23831:tid 23831] [client 104.23.225.125:13960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swhowell.com"] [uri "/.git/config"] [unique_id "apOJCPy2IVM0UiXJzohlywAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 22:25:16
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 18:25:00.232216 2026] [security2:error] [pid 22506:tid 22506] [client 104.23.225.125:11914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.acupressbooks.com"] [uri "/.git/config"] [unique_id "apNcPDLcprDwH3Z8dg_tzwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 11:21:36
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:21:30.677911 2026] [security2:error] [pid 11929:tid 11929] [client 104.23.225.125:12204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "catholicshoppercom.frankpollicino.com"] [uri "/.git/config"] [unique_id "apLAuplXdu-1YTwqFjFIfAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:11:37
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:11:33.539039 2026] [security2:error] [pid 12923:tid 12923] [client 104.23.225.125:9735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobileonlinecasinos.co"] [uri "/.git/config"] [unique_id "apFs5fpeD-XNXccmsORjTgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 09:02:34
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 05:02:26.517490 2026] [security2:error] [pid 29789:tid 29899] [client 104.23.225.125:11789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.triestemagica.org"] [uri "/.git/config"] [unique_id "apFOon6seQRxpYKlqhY8HAAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 07:45:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:44:57.076672 2026] [security2:error] [pid 1298:tid 1298] [client 104.23.225.125:10154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rums-of-the-world.com"] [uri "/.git/config"] [unique_id "apE8ecUZG46mJFPsMSTvAwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-28 02:23:59
(2 weeks ago)
[FriAug2804:23:57.6411892026][security2:error][pid2012041:tid2012160][client104.23.225.125:0]ModSecu ...
show more
[FriAug2804:23:57.6411892026][security2:error][pid2012041:tid2012160][client104.23.225.125:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"grigorov.ch\"][uri\"/.git/config\"][unique_id\"apDxPVBWrKCzBvXRg0UfPAAAAQg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-27 13:08:56
(2 weeks ago)
cloudlinux2 fail2ban: 2026-08-27 15:04:54,241 fail2ban.filter [1775]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-27 15:04:54,241 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 104.23.225.124 - 2026-08-27 15:04:53cloudlinux2 fail2ban: 2026-08-27 15:04:54,228 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 104.23.225.125 - 2026-08-27 15:04:53cloudlinux2 fail2ban: 2026-08-27 15:05:15,080 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.181.170.61 - 2026-08-27 15:05:14cloudlinux2 fail2ban: 2026-08-27 15:05:30,866 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 67.223.118.121 - 2026-08-27 15:05:30cloudlinux2 fail2ban: 2026-08-27 15:05:47,751 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 69.57.162.82 - 2026-08-27 15:05:47cloudlinux2 fail2ban: 2026-08-27 15:05:52,085 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Unban 34.30.200.241cloudlinux2 fail2ban: 2026-08-27 15:06:02,109 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Unban 49.47.129.152cloudlinux2 fail2ban: 2026-08-27 15:06:21
show less
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-08-27 06:11:18
(2 weeks ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 23:32:40
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:32:35.029642 2026] [security2:error] [pid 22404:tid 22404] [client 104.23.225.125:11534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.davidocchino.com"] [uri "/.git/HEAD"] [unique_id "ao93k9lgZSaux-zaYSJ69wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 07:50:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:50:39.962600 2026] [security2:error] [pid 11331:tid 11331] [client 104.23.225.125:10951] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jirafx.aktkaro.com"] [uri "/.git/HEAD"] [unique_id "ao6az-pI90YMUY4gzfXC0gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack