๐บ๐ธ
TPI-Abuse
2026-10-07 11:31:17
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 07:31:12.269645 2026] [security2:error] [pid 21532:tid 21532] [client 172.105.158.249:55060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.snowmanchristmascards.net"] [uri "/.git/info/refs"] [unique_id "asYtgA006hsqtmNarY_yXgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Epimetheus
2026-10-07 04:56:31
(8 hours ago)
Unauthorized access attempts:
[GET] /.git/info/refs
UA: git/2.43.0
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 17:29:41
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 13:29:38.204575 2026] [security2:error] [pid 9119:tid 9119] [client 172.105.158.249:58170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "contrarianadvisors.com"] [uri "/.git/info/refs"] [unique_id "asUwAle_R1nlGbYn7L5MPAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:39:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:39:23.196993 2026] [security2:error] [pid 9492:tid 9492] [client 172.105.158.249:34138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.radar24hrs.com"] [uri "/.git/info/refs"] [unique_id "asTd6z6cZAJnwXtMLsB2-QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 08:18:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:18:36.913480 2026] [security2:error] [pid 18140:tid 18140] [client 172.105.158.249:45678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "minetterisquez.com"] [uri "/.git/info/refs"] [unique_id "asSu3IBgM2Ci4BmOJNQtqAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-06 04:04:24
(1 day ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-05 13:27:32
(2 days ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 172.105.158.249 - - [05/Oct/2026:15:27:22 +0200] "GET /.git/info/refs?service=git-upload-pack HTTP/2.0" 404 24900 "-" "git/2.43.0"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-04 08:53:12
(3 days ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 172 ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 172.105.158.249 - - \[04/Oct/2026:10:52:51 +0200\] "GET /.git/info/refs\?service=git-upload-pack HTTP/1.1" 404 5624 "-" "git/2.43.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 10:15:23
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 06:15:20.098257 2026] [security2:error] [pid 16391:tid 16391] [client 172.105.158.249:38054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anniesherbals.com"] [uri "/.git/info/refs"] [unique_id "asDVuPQd6OIef2pxDZkV-AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2026-10-02 16:19:38
(4 days ago)
tcp/443; Git smart-HTTP repository clone attempt against an exposed .git directory (/.git/info/refs? ...
show more
tcp/443; Git smart-HTTP repository clone attempt against an exposed .git directory (/.git/info/refs?service=git-upload-pack): "GET /.git/info/refs?service=git-upload-pack" @ 2026-10-02T16:19:38Z [proxy]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 03:19:20
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:19:12.587843 2026] [security2:error] [pid 24335:tid 24335] [client 172.105.158.249:60830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.replacementairfilter.com"] [uri "/.git/info/refs"] [unique_id "ar8isIJkD9HcQLvtsfpI9AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
JustMeHere
2026-09-30 06:51:48
(1 week ago)
[Wed Sep 30 02:51:44.681615 2026] [security2:error] [pid 805:tid 957] [client 172.105.158.249:49638] ...
show more
[Wed Sep 30 02:51:44.681615 2026] [security2:error] [pid 805:tid 957] [client 172.105.158.249:49638] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "www.yorknation.com"] [uri "/.git/info/refs"] [unique_id "aryxgJ2-GnwYoNsBZrhxwwAAAI0"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:27:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:27:46.051835 2026] [security2:error] [pid 19682:tid 19682] [client 172.105.158.249:37486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "designamb.com"] [uri "/.git/info/refs"] [unique_id "arwtUrz0y4gxVHxWQxBKWAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 15:45:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 11:44:58.933815 2026] [security2:error] [pid 10275:tid 10318] [client 172.105.158.249:55688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rudimentseq.com"] [uri "/.git/info/refs"] [unique_id "arvc-tIByaHKDUVjvs6PRAAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 08:13:36
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.249 (172-105-158-249.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 04:13:29.051216 2026] [security2:error] [pid 7136:tid 7143] [client 172.105.158.249:42620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stridemechanics.com"] [uri "/.git/info/refs"] [unique_id "artzKRdWzdq_yIPquMKLagAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack