๐บ๐ธ
TPI-Abuse
2026-08-30 00:09:38
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 20:09:32.890889 2026] [security2:error] [pid 18252:tid 18252] [client 104.23.225.178:11409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.willmarksynthetics.cosentient.com"] [uri "/.git/config"] [unique_id "apN0vOmXriKdd7aoFS3gnAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 17:06:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 13:06:35.187528 2026] [security2:error] [pid 9425:tid 9425] [client 104.23.225.178:9453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garagemensministry.michaelsabbey.org"] [uri "/.git/HEAD"] [unique_id "apMRmxTy51Pr3OdE2AVUwwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 21:18:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:18:32.182309 2026] [security2:error] [pid 22626:tid 22626] [client 104.23.225.178:13652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "summithost.com"] [uri "/.git/config"] [unique_id "apH7KGWfivUg9kSO1XfOCwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:16:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:16:00.166236 2026] [security2:error] [pid 743681:tid 744364] [client 104.23.225.178:13757] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ucamp.net"] [uri "/.git/HEAD"] [unique_id "apGKEKzKk__5QR0Jy-_CYwAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 01:50:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:50:43.004293 2026] [security2:error] [pid 26275:tid 26275] [client 104.23.225.178:9377] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dianogah.com"] [uri "/.git/config"] [unique_id "apDpc5lxJ40YMsCS3vNGEgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-25 23:38:55
(4 days ago)
cloudlinux2 fail2ban: 2026-08-26 01:34:11,959 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-26 01:34:11,959 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.225.178 - 2026-08-26 01:34:11cloudlinux2 fail2ban: 2026-08-26 01:34:11,947 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.225.178 - 2026-08-26 01:34:11cloudlinux2 fail2ban: 2026-08-26 01:34:49,186 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Unban 35.188.151.45cloudlinux2 fail2ban: 2026-08-26 01:34:49,091 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 217.181.76.189 - 2026-08-26 01:34:49cloudlinux2 fail2ban: 2026-08-26 01:34:54,599 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.82.92 - 2026-08-26 01:34:54cloudlinux2 fail2ban: 2026-08-26 01:34:52,009 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 213.108.0.253 - 2026-08-26 01:34:51cloudlinux2 fail2ban: 2026-08-26 01:34:57,478 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.12.47 - 2026-08-26 01:34:57cloudlinux2 fail2ban:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 19:42:14
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 15:42:10.317879 2026] [security2:error] [pid 13662:tid 13662] [client 104.23.225.178:11514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arthuregau.com"] [uri "/.git/HEAD"] [unique_id "ao3wEvgEKgUOufDFVoqKCQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 19:19:58
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 15:19:54.309875 2026] [security2:error] [pid 7538:tid 7538] [client 104.23.225.178:10009] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nancybcatering.com"] [uri "/.git/config"] [unique_id "ao3q2rnAEveOHhxbx5iipQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-08-25 18:54:08
(4 days ago)
104.23.225.178 - - [25/Aug/2026:20:54:07 +0200] "GET /.git/HEAD HTTP/2.0" 404 275 "-" "Mozilla/5.0 ( ...
show more
104.23.225.178 - - [25/Aug/2026:20:54:07 +0200] "GET /.git/HEAD HTTP/2.0" 404 275 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 18:06:35
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 14:06:27.625825 2026] [security2:error] [pid 31456:tid 31456] [client 104.23.225.178:9698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.speedgo.mx"] [uri "/.git/config"] [unique_id "ao3Zo_czMO7ILIiIVs0DuAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 11:55:52
(5 days ago)
104.23.225.178 - - [25/Aug/2026:11:55:51 +0000] "GET /.git/config HTTP/1.1" 404 52427 "-" "Mozilla/5 ...
show more
104.23.225.178 - - [25/Aug/2026:11:55:51 +0000] "GET /.git/config HTTP/1.1" 404 52427 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-25 11:09:37
(5 days ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-25 10:04:33
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:04:28.009026 2026] [security2:error] [pid 23058:tid 23058] [client 104.23.225.178:9934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.puckerbikinis.com"] [uri "/.git/HEAD"] [unique_id "ao1orIdvCVFrniN9P_sYGQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 09:48:39
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:48:35.445732 2026] [security2:error] [pid 28176:tid 28176] [client 104.23.225.178:14207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.lemontreefoods.com"] [uri "/.git/HEAD"] [unique_id "ao1k88OyH6wziiFZYwhDFwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-24 22:30:04
(5 days ago)
[TueAug2500:29:58.5359872026][security2:error][pid1638966:tid1639006][client104.23.225.178:0]ModSecu ...
show more
[TueAug2500:29:58.5359872026][security2:error][pid1638966:tid1639006][client104.23.225.178:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"traslocareinsvizzera.ch\"][uri\"/.git/config\"][unique_id\"aozF5j9N4wLlQpYl9nqhPQAAAEM\"]
show less
Port Scan
Brute-Force
Web App Attack