πΊπΈ
TPI-Abuse
2026-07-24 23:33:27
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 19:33:24.163851 2026] [security2:error] [pid 19582:tid 19582] [client 140.248.75.87:4730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bzbdesigns.com"] [uri "/.git/HEAD"] [unique_id "amP2RI5oh6yMfBtnTMZdQgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 19:02:21
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:02:16.968796 2026] [security2:error] [pid 1038651:tid 1038651] [client 140.248.75.87:34678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.directoryofgems.com"] [uri "/.git/HEAD"] [unique_id "amO2uOZIETDz_Ly1-VylOwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
TheCoon
2026-07-24 00:15:01
(1 day ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-07-23 23:51:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 19:51:14.476549 2026] [security2:error] [pid 120280:tid 120328] [client 140.248.75.87:31870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.truthjusticecommission.com"] [uri "/.git/HEAD"] [unique_id "amKo8pVtjatySO8rXv8zQQAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
mail.avx.gr
2026-07-23 11:29:15
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 140.248.75.87 - - [19/Jul/20 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 140.248.75.87 - - [19/Jul/2026:00:51:10 +0300] "GET /.git/config HTTP/1.1" 403 2425 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
show less
Web App Attack
π§πͺ
voormedia
2026-07-22 18:10:54
(2 days ago)
Accessed trap at '/.git/HEAD'
Web App Attack
π¬π§
Axel
2026-07-22 12:35:53
(2 days ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/HEAD Se ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/HEAD Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
π¨π±
SinaiCL
2026-07-22 03:55:13
(2 days ago)
WAF Multiple Hits
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-07-21 13:58:12
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-21 08:41:11
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 04:41:08.452286 2026] [security2:error] [pid 4167370:tid 4167370] [client 140.248.75.87:34400] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "freedrm.org"] [uri "/.git/HEAD"] [unique_id "al8wpKuDSh1EHfbRZzVCvwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-07-20 18:16:14
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 10:52:07
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 06:52:03.349180 2026] [security2:error] [pid 31969:tid 31969] [client 140.248.75.87:59724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cayman-islands-real-estate.com"] [uri "/.git/config"] [unique_id "al3900MuUkdkvTsgC9hBPgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 10:05:47
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 06:05:41.612777 2026] [security2:error] [pid 21130:tid 21130] [client 140.248.75.87:23680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.northamericantrucking.com"] [uri "/.git/config"] [unique_id "al3y9WrgLD8fkskjs54rXwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 06:37:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 02:37:25.346681 2026] [security2:error] [pid 23578:tid 23578] [client 140.248.75.87:25812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waynos.net"] [uri "/.git/config"] [unique_id "al3CJVVodI46STyvmH2GeAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 22:29:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 18:29:28.624381 2026] [security2:error] [pid 24170:tid 24170] [client 140.248.75.87:3062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tobyscott.com"] [uri "/.git/config"] [unique_id "al1PyGfMlo8K1tZ5e1nXbAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack