Anonymous
2026-09-15 19:35:56
(15 hours ago)
"GET /.git/HEAD HTTP/1.1"
Hacking
Web App Attack
π³π±
Alt255
2026-09-15 12:27:30
(22 hours ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 144.172.108.73 - - [15/Sep/2026:14:27:19 +0200] "GET /.git/HEAD HTTP/1.1" 404 28168 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-09-15 11:47:42
(23 hours ago)
[TueSep1513:47:36.2857082026][security2:error][pid3207677:tid3207751][client144.172.108.73:0]ModSecu ...
show more
[TueSep1513:47:36.2857082026][security2:error][pid3207677:tid3207751][client144.172.108.73:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"parrocchiaditesserete.ch\"][uri\"/.git/HEAD\"][unique_id\"aqkwWCetDcB44qu0z5_9gwAAAI0\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 11:09:10
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6c49::90ac:6c49 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6c49::90ac:6c49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:09:07.376505 2026] [security2:error] [pid 13441:tid 13441] [client 2002:90ac:6c49::90ac:6c49:60047] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dick-schoonover.com"] [uri "/.git/HEAD"] [unique_id "aqknU9txW3mmS-6kEKubSQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 10:49:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6c49::90ac:6c49 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6c49::90ac:6c49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:49:39.107085 2026] [security2:error] [pid 24075:tid 24075] [client 2002:90ac:6c49::90ac:6c49:58595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "instagenii.com"] [uri "/.git/HEAD"] [unique_id "aqkiwyfUeYhxbZNuroxocQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 10:27:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6c49::90ac:6c49 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6c49::90ac:6c49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:27:26.713537 2026] [security2:error] [pid 10215:tid 10215] [client 2002:90ac:6c49::90ac:6c49:49856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "k-h-w.com"] [uri "/.git/HEAD"] [unique_id "aqkdjvoQFAntS68aV_8D4wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-15 10:17:52
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/HEAD | 2026-09-15 10:17 UTC
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 09:28:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 144.172.108.73 (73.108.172.144.static.cloudzy.c ...
show more
(mod_security) mod_security (id:210492) triggered by 144.172.108.73 (73.108.172.144.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:28:54.090784 2026] [security2:error] [pid 4042:tid 4042] [client 144.172.108.73:54549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peterjohnsonauthor.com"] [uri "/.git/HEAD"] [unique_id "aqkP1ktdNML5AK62xpnEDwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 09:02:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 144.172.108.73 (73.108.172.144.static.cloudzy.c ...
show more
(mod_security) mod_security (id:210492) triggered by 144.172.108.73 (73.108.172.144.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:02:07.751475 2026] [security2:error] [pid 21956:tid 21956] [client 144.172.108.73:58178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dansplans.com"] [uri "/.git/HEAD"] [unique_id "aqkJj6LhyLYi7oEAVAfXZQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-15 08:48:37
(1 day ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 144.172.108.73 - - [15/Sep/2026:10:48:36 +0200] "GET /en/.git/HEAD HTTP/1.1" 403 7799 "https://e-amturning.com/.git/HEAD" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π«π·
pm33
2026-09-15 08:39:10
(1 day ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
π©πͺ
Bedios GmbH
2026-09-15 08:20:29
(1 day ago)
Login credentials theft attempt
Hacking
πΊπΈ
TPI-Abuse
2026-09-15 08:20:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 144.172.108.73 (73.108.172.144.static.cloudzy.c ...
show more
(mod_security) mod_security (id:210492) triggered by 144.172.108.73 (73.108.172.144.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:19:53.064911 2026] [security2:error] [pid 634940:tid 634940] [client 144.172.108.73:51160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artocratic.com"] [uri "/.git/HEAD"] [unique_id "aqj_qcJ7eIPicezVNVvMqQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 07:50:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 144.172.108.73 (73.108.172.144.static.cloudzy.c ...
show more
(mod_security) mod_security (id:210492) triggered by 144.172.108.73 (73.108.172.144.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:50:15.649331 2026] [security2:error] [pid 17666:tid 17666] [client 144.172.108.73:50267] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dyslexiaspecialistsonline.com"] [uri "/.git/HEAD"] [unique_id "aqj4t9-kKSOOqs9gUbU-VQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 06:50:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 144.172.108.73 (73.108.172.144.static.cloudzy.c ...
show more
(mod_security) mod_security (id:210492) triggered by 144.172.108.73 (73.108.172.144.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:50:28.861421 2026] [security2:error] [pid 32750:tid 304] [client 144.172.108.73:58015] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amphoracollectors.org"] [uri "/.git/HEAD"] [unique_id "aqjqtMHU10flfW3O2TG4-QAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack