๐บ๐ธ
TPI-Abuse
2026-08-28 04:58:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:58:49.212007 2026] [security2:error] [pid 11947:tid 11947] [client 104.23.225.50:14069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.scottwithers.net"] [uri "/.git/config"] [unique_id "apEVibgX5dwBx7Y2bdPOIAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 04:41:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:41:43.159490 2026] [security2:error] [pid 9915:tid 9915] [client 104.23.225.50:13502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.uulaw.net"] [uri "/.git/config"] [unique_id "apERhz-dDGBKISptD6wc4gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 09:54:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:53:56.451358 2026] [security2:error] [pid 28347:tid 28347] [client 104.23.225.50:10322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.frankweyer.com"] [uri "/.git/HEAD"] [unique_id "ao63tMubOlNI0M9RfCZqQAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 08:45:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:45:01.048927 2026] [security2:error] [pid 3721629:tid 3722082] [client 104.23.225.50:12228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hoffmanandassoc.com"] [uri "/.git/HEAD"] [unique_id "ao6njbycJv2bkUkw0ARDYwAAAcs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-25 23:23:56
(3 days ago)
cloudlinux2 fail2ban: 2026-08-26 01:19:44,142 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-26 01:19:44,142 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.225.51 - 2026-08-26 01:19:43cloudlinux2 fail2ban: 2026-08-26 01:19:44,154 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.225.50 - 2026-08-26 01:19:43cloudlinux2 fail2ban: 2026-08-26 01:20:17,389 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.86.28 - 2026-08-26 01:20:16cloudlinux2 fail2ban: 2026-08-26 01:20:14,660 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 217.181.73.183 - 2026-08-26 01:20:14cloudlinux2 fail2ban: 2026-08-26 01:20:19,605 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.86.22 - 2026-08-26 01:20:19cloudlinux2 fail2ban: 2026-08-26 01:20:18,760 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.83.58 - 2026-08-26 01:20:18cloudlinux2 fail2ban: 2026-08-26 01:20:16,771 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.64.231 - 2026-08-26 01:20:16c
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 23:20:15
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 19:20:05.601139 2026] [security2:error] [pid 22999:tid 22999] [client 104.23.225.50:14081] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "books.freedrm.org"] [uri "/.git/config"] [unique_id "ao4jJYVzng1-IgJAIL1Z4wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 14:43:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 10:43:20.603764 2026] [security2:error] [pid 10381:tid 10381] [client 104.23.225.50:13742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.equipoperu.org"] [uri "/.git/HEAD"] [unique_id "ao2qCHTyP-wof4Fd7UnP6gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 14:03:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 10:02:58.453320 2026] [security2:error] [pid 32197:tid 32197] [client 104.23.225.50:12197] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.creektech.com"] [uri "/.git/HEAD"] [unique_id "ao2gktmhzL288wDfIahTQAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 11:11:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 07:11:39.573567 2026] [security2:error] [pid 7170:tid 7170] [client 104.23.225.50:9797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kccares.help"] [uri "/.git/HEAD"] [unique_id "ao14a9xN9jG1hJrjky4sjwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 10:44:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:44:09.789691 2026] [security2:error] [pid 18770:tid 18770] [client 104.23.225.50:11812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.celiaisrock.com"] [uri "/.git/config"] [unique_id "ao1x-V9bgeZ5d7uobNKdZwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 22:56:44
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 18:56:39.116812 2026] [security2:error] [pid 1010:tid 1049] [client 104.23.225.50:11287] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.piazzala.piazza9.com"] [uri "/.git/config"] [unique_id "aot6pxCaOOFlCcBn03bmMQAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 22:12:55
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 18:12:50.984205 2026] [security2:error] [pid 11029:tid 11029] [client 104.23.225.50:11963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michelle.mathewyoung.com"] [uri "/.git/config"] [unique_id "aotwYpzMkTyEMX1kQxl9bAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CBJ
2026-08-23 14:35:53
(5 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-23 08:11:21
(5 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 21:39:59
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 17:39:55.316905 2026] [security2:error] [pid 31694:tid 31694] [client 104.23.225.50:13927] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.faeriefeelers.com"] [uri "/.git/HEAD"] [unique_id "aooXK23hO2aIFcb3laL2HwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack