๐ฉ๐ช
big-cloud.nl
2026-07-22 17:44:57
(1 day ago)
Try to access /.git/HEAD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 13:56:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 09:56:21.732213 2026] [security2:error] [pid 213972:tid 213972] [client 157.52.92.96:40886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naomipyle.com"] [uri "/.git/config"] [unique_id "amDMBXcYVMKWMGTpcDgoEAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-22 00:09:59
(2 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 22:41:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 18:41:07.483277 2026] [security2:error] [pid 1013565:tid 1013565] [client 157.52.92.96:29662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jazzycatty.com"] [uri "/.git/HEAD"] [unique_id "al_1g0JJHiRymB34O_AzLgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 20:34:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 16:34:52.942999 2026] [security2:error] [pid 15565:tid 15565] [client 157.52.92.96:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.triplejrealty.com"] [uri "/.git/HEAD"] [unique_id "al_X7Pxgauw_LBfv5wjh9gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 20:12:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 16:12:02.170091 2026] [security2:error] [pid 21462:tid 21462] [client 157.52.92.96:58296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tradersworldmarket.com"] [uri "/.git/HEAD"] [unique_id "al_SkggP-cx1rEfrNzHNfAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-21 19:08:19
(2 days ago)
[TueJul2121:08:15.6882312026][security2:error][pid3633070:tid3633088][client157.52.92.96:0]ModSecuri ...
show more
[TueJul2121:08:15.6882312026][security2:error][pid3633070:tid3633088][client157.52.92.96:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.autoeuro.lv\"][uri\"/.git/HEAD\"][unique_id\"al_DnzBqVGboae8jL77IbgAAAA8\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 17:15:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 13:14:58.838027 2026] [security2:error] [pid 27421:tid 27421] [client 157.52.92.96:58018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kurikka.eu"] [uri "/.git/HEAD"] [unique_id "al-pEleQwDJ04t-dE9-OmwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-21 12:30:14
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
lnklnx
2026-07-21 08:58:54
(3 days ago)
www.lincolnclan.com:443 157.52.92.96 - - [21/Jul/2026:03:58:51 -0500] "GET /.git/HEAD HTTP/1.1" 401 ...
show more
www.lincolnclan.com:443 157.52.92.96 - - [21/Jul/2026:03:58:51 -0500] "GET /.git/HEAD HTTP/1.1" 401 4072 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:57:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:57:11.919976 2026] [security2:error] [pid 24131:tid 24131] [client 157.52.92.96:23164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thehealthyplaceclayton.com"] [uri "/.git/HEAD"] [unique_id "al611yUDtkX4apM33VVCywAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:24:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:24:49.126569 2026] [security2:error] [pid 9709:tid 9709] [client 157.52.92.96:36232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "old.renju.net"] [uri "/.git/HEAD"] [unique_id "al6uQbzwy1XAcDqOHn0w3gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-07-20 21:59:24
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 157.52.92.96 (SG/Singapore/-): N in the last X ...
show more
(mod_security) mod_security (id:949110) triggered by 157.52.92.96 (SG/Singapore/-): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 19:12:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 15:11:59.982080 2026] [security2:error] [pid 5253:tid 5253] [client 157.52.92.96:50096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toptek.com"] [uri "/.git/HEAD"] [unique_id "al5y_3sMPhcLLjf-CsNbLwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 19:06:05
(3 days ago)
Trying to access config files
Web App Attack