๐บ๐ธ
TPI-Abuse
2026-09-13 21:17:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.c ...
show more
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.cy): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 17:17:16.643532 2026] [security2:error] [pid 19051:tid 19051] [client 128.0.241.150:33760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srosa.danged.com"] [uri "/.git/config"] [unique_id "aqcS3IFvl5i0HxA3n4BHIAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2026-09-12 13:52:16
(2 weeks ago)
common Web Exploits being scanned
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-12 12:31:35
(2 weeks ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 128.0.241.150 (CY/Cyprus/128-241-15 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 128.0.241.150 (CY/Cyprus/128-241-150.netrun.cytanet.com.cy): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 09:07:56
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.c ...
show more
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.cy): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:07:50.261591 2026] [security2:error] [pid 4655:tid 4655] [client 128.0.241.150:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.365soft.top"] [uri "/.git/config"] [unique_id "aqUWZgRX3qbBEUyZFRILKAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-10 20:33:13
(2 weeks ago)
Accessed trap at '/.git/config'
Web App Attack
๐ฉ๐ช
paissangroup
2026-09-10 14:21:16
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 10:08:54
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.c ...
show more
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.cy): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 06:08:50.806523 2026] [security2:error] [pid 26568:tid 26568] [client 128.0.241.150:43588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nickersoncarpentry.modeltdr.com"] [uri "/.git/config"] [unique_id "aqKBsqc_bBa2W2Ah_QNfPgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 07:57:31
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.c ...
show more
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.cy): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 03:57:26.280665 2026] [security2:error] [pid 29729:tid 29779] [client 128.0.241.150:13626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.adprospb.com"] [uri "/.git/config"] [unique_id "aqJi5v3vFfF91x90m0ylswAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-09 23:20:04
(2 weeks ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-09 23:16:14
(2 weeks ago)
128.0.241.150 - - [10/Sep/2026:01:16:11 +0200] "GET /.git/config HTTP/1.1" 403 4524 "-" "Go-http-cli ...
show more
128.0.241.150 - - [10/Sep/2026:01:16:11 +0200] "GET /.git/config HTTP/1.1" 403 4524 "-" "Go-http-client/1.1"
128.0.241.150 - - [10/Sep/2026:01:16:11 +0200] "GET /.git/config HTTP/1.1" 301 573 "-" "Go-http-client/1.1"
128.0.241.150 - - [10/Sep/2026:01:16:12 +0200] "GET /.git/config HTTP/1.1" 403 4524 "http://[site]/.git/config" "Go-http-client/1.1"
show less
Web App Attack
Hacking
๐ซ๐ฎ
inlink.ltd
2026-09-09 20:04:45
(2 weeks ago)
dot file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 16:40:52
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.c ...
show more
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.cy): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:40:48.745952 2026] [security2:error] [pid 22717:tid 22717] [client 128.0.241.150:60332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infinitewashingsolutions.finishlineenterprisesllc.com"] [uri "/.git/config"] [unique_id "aqGMEP4YrXmaFmxriessOwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 09:26:15
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.c ...
show more
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.cy): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:26:11.055583 2026] [security2:error] [pid 30011:tid 30011] [client 128.0.241.150:27502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.scrood.fm"] [uri "/.git/config"] [unique_id "aqEmMxEw7xMJmDX_Kle9kQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 07:22:34
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.c ...
show more
(mod_security) mod_security (id:210492) triggered by 128.0.241.150 (128-241-150.netrun.cytanet.com.cy): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:22:30.883047 2026] [security2:error] [pid 24576:tid 24576] [client 128.0.241.150:11066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tacanicsa.com"] [uri "/.git/config"] [unique_id "aqEJNrXrT9pkQDY8aw393QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-09-08 13:16:49
(2 weeks ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack