πΊπΈ
TPI-Abuse
2026-08-27 20:36:34
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:36:30.720089 2026] [security2:error] [pid 26017:tid 26017] [client 108.162.242.79:13861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vetline.eu"] [uri "/.git/config"] [unique_id "apCfzlwt1BsXEnxmCgcOEwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 19:27:59
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:27:51.779155 2026] [security2:error] [pid 16410:tid 16410] [client 108.162.242.79:13316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.utd.net"] [uri "/.git/HEAD"] [unique_id "apCPt0WyfD67PGm_GL-ZjwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 01:25:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 21:25:08.350292 2026] [security2:error] [pid 1264:tid 1264] [client 108.162.242.79:9999] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brasscadillac.com"] [uri "/.git/HEAD"] [unique_id "ao-R9E-7B_uWKSUHLmPffAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 18:54:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:54:22.488694 2026] [security2:error] [pid 15060:tid 15060] [client 108.162.242.79:13183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kriske.com"] [uri "/.git/HEAD"] [unique_id "ao82XoZf01zaxlYxTP16BAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-16 10:05:20
(2 weeks ago)
Web App Attack
π¦π±
router.al
2026-08-02 22:29:50
(1 month ago)
08/02/2026-22:29:50.432042 108.162.242.79 Protocol: 6 ET WEB_SERVER Tilde in URI - potential .php~ s ...
show more
08/02/2026-22:29:50.432042 108.162.242.79 Protocol: 6 ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
show less
Hacking
π¦π±
router.al
2026-07-31 10:44:16
(1 month ago)
07/31/2026-10:44:16.600979 108.162.242.79 Protocol: 6 ET EXPLOIT GraphQL Introspection Query Attempt
Hacking
π©πͺ
webanyone
2026-07-28 07:00:58
(1 month ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-29 23:58:09
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 19:58:02.182718 2026] [security2:error] [pid 27028:tid 27028] [client 108.162.242.79:10612] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.merrittconst.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.merrittconst.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "akMGikB2FKFAom4ys5WAGAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-06-10 22:02:41
(2 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-09.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-05-29 11:54:48
(3 months ago)
Aggressive web scan
Web App Attack
π©πͺ
webanyone
2026-05-23 20:30:16
(3 months ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-21 17:05:21
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 108.162.242.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 13:05:06.895280 2026] [security2:error] [pid 2664:tid 2664] [client 108.162.242.79:13750] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.buddysinflatables.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.buddysinflatables.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ag87QqusOTwDYfFZTXTn7QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-10 21:27:26
(3 months ago)
Crappy bot probing nonexistent /wp-includes/images/wp-login.php
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-29 04:51:15
(4 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack