Anonymous
2026-09-23 16:52:09
(5 hours ago)
[osotir.org] httpd-config-scan: sites=www.ear-books.com; logs=/var/log/httpd/domains/ear-books.com.l ...
show more
[osotir.org] httpd-config-scan: sites=www.ear-books.com; logs=/var/log/httpd/domains/ear-books.com.log; samples=/.git/HEAD
show less
Hacking
Web App Attack
๐บ๐ธ
CBJ
2026-09-23 14:42:10
(7 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 12:31:33
(10 hours ago)
[23/Sep/2026:15:31:33 +0300] -- 107.172.81.254 Ban reason: User-Agent Python-urllib
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:44:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:44:30.293790 2026] [security2:error] [pid 26977:tid 26977] [client 107.172.81.254:37819] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.foamnoodlejousting.windisfun.com"] [uri "/.git/HEAD"] [unique_id "arI_7qFmNKvq8pKmIF4HVAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 06:07:18
(1 day ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/HEAD | 2026-09-22 06:07 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:59:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:59:48.504248 2026] [security2:error] [pid 3187:tid 3217] [client 107.172.81.254:59300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trident-environmental.com"] [uri "/.git/HEAD"] [unique_id "arCdpEtJrWe6JJdwU9vbowAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-18 22:19:22
(5 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 19:43:09
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 15:42:19.819429 2026] [security2:error] [pid 6152:tid 6170] [client 107.172.81.254:52391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mastersdegreetaxation.com.aafm.us"] [uri "/.git/HEAD"] [unique_id "aq2UGzsGwbIAq3aRhfA84AAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
FreeMyIP
2026-09-18 09:15:06
(5 days ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:08:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:08:27.136517 2026] [security2:error] [pid 456:tid 456] [client 107.172.81.254:34638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sof.aarce.me"] [uri "/.git/HEAD"] [unique_id "aqoyW1nFoXFvJXkykuZRIQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:01:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:01:43.870246 2026] [security2:error] [pid 25681:tid 25681] [client 107.172.81.254:37104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.babylontravelone.com"] [uri "/.git/HEAD"] [unique_id "aqkXh_x2gbZOKN38opmdMAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 09:35:46
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 107.172.81.254 (107-172-81-254-host.colocrossin ...
show more
(mod_security) mod_security (id:949110) triggered by 107.172.81.254 (107-172-81-254-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:35:34.611120 2026] [security2:error] [pid 14143:tid 14143] [client 107.172.81.254:41446] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.motonaonaobookings.hamiltonbookings.com"] [uri "/.git/HEAD"] [unique_id "aqkRZmfCmh1Pvea2ApF6oAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 20:43:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 16:43:21.743369 2026] [security2:error] [pid 9242:tid 9242] [client 107.172.81.254:59124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.davidwoodard.com"] [uri "/.git/HEAD"] [unique_id "aqhcaaMhq99hNj8FQ_QQYgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 01:33:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 21:33:23.467733 2026] [security2:error] [pid 14574:tid 14574] [client 107.172.81.254:57731] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dhappraisalservices.com"] [uri "/.git/HEAD"] [unique_id "aqdO4xe9hiixzZXg5cK_6AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 19:42:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.172.81.254 (107-172-81-254-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 15:42:08.576523 2026] [security2:error] [pid 15592:tid 15592] [client 107.172.81.254:34505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.comitedelafamille.org"] [uri "/.git/HEAD"] [unique_id "aqb8kAtgsyQFf_R6L1klxAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack