๐บ๐ธ
TPI-Abuse
2026-10-08 09:40:16
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:40:09.845856 2026] [security2:error] [pid 18051:tid 18051] [client 107.172.130.85:49146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nexthop.com"] [uri "/.git/HEAD"] [unique_id "asdk-Ssr7Tyfv3hFUEznrwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 09:24:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:24:06.638553 2026] [security2:error] [pid 28007:tid 28007] [client 107.172.130.85:55798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cmabiblequizzing.org"] [uri "/.git/HEAD"] [unique_id "asdhNkdZDnAGvE8l4yp6bAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 04:16:16
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 00:16:04.190229 2026] [security2:error] [pid 27664:tid 27664] [client 107.172.130.85:33848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "open.evolute.io"] [uri "/.git/HEAD"] [unique_id "ascZBGyopnFpgKSEmCbJqgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-08 02:32:16
(12 hours ago)
[ThuOct0804:32:10.6477472026][security2:error][pid1698588:tid1698660][client107.172.130.85:0]ModSecu ...
show more
[ThuOct0804:32:10.6477472026][security2:error][pid1698588:tid1698660][client107.172.130.85:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"www.vivereiltrentino.it\"][uri\"/.git/HEAD/\"][unique_id\"ascAqu3nnBDBmm78OCNahgAAAIY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:38:09
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:37:59.857935 2026] [security2:error] [pid 32449:tid 32449] [client 107.172.130.85:54308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.natickvillagerentals.com"] [uri "/.git/HEAD"] [unique_id "asbl57SqCG70c5wHmwdzuQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 12:58:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 08:58:04.537224 2026] [security2:error] [pid 6694:tid 6711] [client 107.172.130.85:46016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howardhallis.com"] [uri "/.git/HEAD"] [unique_id "asZB3Pkjh6SAbuR-BtzDxAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 01:36:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:36:34.631524 2026] [security2:error] [pid 6585:tid 6630] [client 107.172.130.85:37263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "energy.brucejoell.com"] [uri "/.git/HEAD"] [unique_id "asWiIutqZxVttfvCVp6ijwAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-06 13:42:12
(2 days ago)
[cb-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 107.172.130.85 - - [06/Oct/2026:15:41:51 +0200] "GET /.git/HEAD HTTP/1.1" 301 466 "-" "Python-urllib/3.10"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-06 10:55:27
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 03:22:41
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:22:33.137998 2026] [security2:error] [pid 30658:tid 30658] [client 107.172.130.85:57197] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.bitcoinsubscribers.com"] [uri "/.git/HEAD"] [unique_id "ar8jeeX6M3S3bx2AcXl8FQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 02:28:26
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 22:28:19.032326 2026] [security2:error] [pid 17863:tid 17863] [client 107.172.130.85:51047] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.coinbracelet.com"] [uri "/.git/HEAD"] [unique_id "ar8WwxVz-P4ZloqzDWeyDQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 11:37:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 07:37:53.510726 2026] [security2:error] [pid 23020:tid 23042] [client 107.172.130.85:39095] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.paygulf.com"] [uri "/.git/HEAD"] [unique_id "arpRkVJ6vvbUh46Fx6ZUfwAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 09:27:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 05:26:47.804079 2026] [security2:error] [pid 26227:tid 26227] [client 107.172.130.85:34382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sagoscapes.com.piratecostumesonline.com"] [uri "/.git/HEAD"] [unique_id "aroy1xo4jpl3nXPlxUsa4wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 12:25:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.130.85 (107-172-130-85-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 08:24:55.480170 2026] [security2:error] [pid 13752:tid 13752] [client 107.172.130.85:53257] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.30daysout.com.kronrod.com"] [uri "/.git/HEAD"] [unique_id "arkLF-t_YORIfjo59wipWgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-27 04:45:59
(1 week ago)
Web probing (1 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CR ...
show more
Web probing (1 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack