🇩🇪
BlueWire Hosting
2026-09-14 22:32:57
(10 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 08:53:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 04:53:41.071847 2026] [security2:error] [pid 28831:tid 28831] [client 107.175.86.194:40975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bodybuildbid.com"] [uri "/.git/HEAD"] [unique_id "aqe2FQ8ipgxjDYXczPrlFAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 03:02:23
(1 day ago)
apache vulnerability scan
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-14 02:02:36
(1 day ago)
[14/Sep/2026:05:02:36 +0300] -- 107.175.86.194 Ban reason: User-Agent Python-urllib
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 17:51:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 13:51:38.648631 2026] [security2:error] [pid 4197:tid 4197] [client 107.175.86.194:48849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.skeletron.com"] [uri "/.git/HEAD"] [unique_id "aqbiqloLoP_UqFjwNWa4EAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 08:23:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:23:41.343708 2026] [security2:error] [pid 21566:tid 21566] [client 107.175.86.194:43991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sxfx.info"] [uri "/.git/HEAD"] [unique_id "aqZdjUVTlnNYnZDy6-x9agAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 01:12:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:11:45.342745 2026] [security2:error] [pid 27324:tid 27324] [client 107.175.86.194:49798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iclog.us.joshuashands.org"] [uri "/.git/HEAD"] [unique_id "aqX4UULjb2iMsvyhDh3JQQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 14:50:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 10:49:57.187675 2026] [security2:error] [pid 23088:tid 23088] [client 107.175.86.194:52098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.papelandia.com.ve"] [uri "/.git/HEAD"] [unique_id "aqVmlY8IuLFPsjpvWPskkQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 17:09:32
(6 days ago)
GET /.git/HEAD HTTP/1.1
...
Web App Attack
🇮🇩
Burayot
2026-09-08 17:06:41
(6 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 107.175.86.194 (US/United States/10 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 107.175.86.194 (US/United States/107-175-86-194-host.colocrossing.com): 1 in the last 3600 secs
show less
Web App Attack
🇩🇪
4server
2026-09-05 13:53:49
(1 week ago)
[SatSep0515:53:46.5603842026][security2:error][pid1611576:tid1611716][client107.175.86.194:0]ModSecu ...
show more
[SatSep0515:53:46.5603842026][security2:error][pid1611576:tid1611716][client107.175.86.194:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"www.ilmiotrentino.it\"][uri\"/403.shtml\"][unique_id\"apwe6hixFiUZpw1LSb-etgAAARU\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-09-05 09:00:02
(1 week ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:48:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 107.175.86.194 (107-175-86-194-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:46:56.623560 2026] [security2:error] [pid 14117:tid 14137] [client 107.175.86.194:47318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.extrememakeovers.us.aafm.us"] [uri "/.git/HEAD"] [unique_id "apsgMJogtjmLlKhyltjnAQAAAZI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 14:56:16
(1 week ago)
[04/Sep/2026:17:56:16 +0300] -- 107.175.86.194 Ban reason: User-Agent Python-urllib
Bad Web Bot
Web App Attack
🇬🇧
Smish
2026-09-04 00:40:44
(1 week ago)
HONEYPOT HIT --> Fail2ban time=1788482442 log=2026-09-04T01:40:42+01:00 ip=107.175.86.194 host=ipam. ...
show more
HONEYPOT HIT --> Fail2ban time=1788482442 log=2026-09-04T01:40:42+01:00 ip=107.175.86.194 host=ipam.as210667.net method=GET uri="/.git/HEAD" status=404 ua="Python-urllib/3.10" ref="-" rid=f6984b095487c0f3c6dac8fc03572545
show less
Web App Attack