๐ฉ๐ช
raph
2026-07-21 22:51:34
(5 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 22:17:54
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 18:17:47.637721 2026] [security2:error] [pid 16002:tid 16002] [client 157.52.92.89:44848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.esslinger.us"] [uri "/.git/HEAD"] [unique_id "al_wC1aJABq4Zg-0Z3zupwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-21 18:38:13
(9 hours ago)
Try to access /.git/HEAD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 18:09:00
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:08:56.655720 2026] [security2:error] [pid 28337:tid 28337] [client 157.52.92.89:62352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kentsavagelaw.com"] [uri "/.git/config"] [unique_id "al-1uBh-f7QBqJt6dnuKPwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-07-21 17:31:22
(10 hours ago)
tcp/443
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-21 16:26:22
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 12:26:18.612466 2026] [security2:error] [pid 12051:tid 12051] [client 157.52.92.89:17040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jackkerrart.com"] [uri "/.git/HEAD"] [unique_id "al-dqpa-JMOyTqUzgZ-lYwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-07-21 16:11:08
(12 hours ago)
tcp/443 (8 or more attempts)
Port Scan
๐ฉ๐ช
ISPLtd
2026-07-21 10:56:12
(17 hours ago)
157.52.92.89 [21/Jul/2026:07:56:10 -0300] www.armadilloservices.ca:443 URL:/.git/HEAD "GET /.git/HEA ...
show more
157.52.92.89 [21/Jul/2026:07:56:10 -0300] www.armadilloservices.ca:443 URL:/.git/HEAD "GET /.git/HEAD
157.52.92.89 [21/Jul/2026:07:56:12 -0300] www.armadilloservices.ca:443 URL:/.git/HEAD "GET /.git/HEAD
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 10:48:01
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 06:47:55.701687 2026] [security2:error] [pid 4631:tid 4631] [client 157.52.92.89:32840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.eagrant.com"] [uri "/.git/HEAD"] [unique_id "al9OW6yvCdArj3_K8ostJAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 00:16:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:16:34.149717 2026] [security2:error] [pid 22540:tid 22540] [client 157.52.92.89:52510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fixitz.net"] [uri "/.git/HEAD"] [unique_id "al66Yhkgzh0W8LLIh_QjhgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 00:00:07
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:24:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:24:29.932866 2026] [security2:error] [pid 1524872:tid 1524872] [client 157.52.92.89:2880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.eeeckythump.net"] [uri "/.git/HEAD"] [unique_id "al6uLYFIbJvmnHmiwEIOwAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 22:44:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 18:44:31.686893 2026] [security2:error] [pid 3718476:tid 3718476] [client 157.52.92.89:35704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stationrestaurant.ca"] [uri "/.git/HEAD"] [unique_id "al6kz1uLzmvEfxtnia3Y_gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-07-20 21:48:21
(1 day ago)
157.52.92.89 - - [20/Jul/2026:23:48:19 +0200] "GET /.git/HEAD HTTP/1.1" 403 5026 "-" "Mozilla/5.0 (X ...
show more
157.52.92.89 - - [20/Jul/2026:23:48:19 +0200] "GET /.git/HEAD HTTP/1.1" 403 5026 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 18:38:20
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:949110) triggered by 157.52.92.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 14:38:13.115536 2026] [security2:error] [pid 3355993:tid 3355993] [client 157.52.92.89:36236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "equiprentalsales.crazycontrols.com"] [uri "/.git/HEAD"] [unique_id "al5rFWSlHcsqQaRZ15YyhwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack