๐บ๐ธ
TPI-Abuse
2026-07-22 12:13:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 08:13:53.561520 2026] [security2:error] [pid 785426:tid 785426] [client 172.111.80.131:16928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forwardti.com"] [uri "/.git/HEAD"] [unique_id "amC0AbKLnVar7nRgwztjNgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 00:34:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:34:00.413600 2026] [security2:error] [pid 1583233:tid 1583233] [client 172.111.80.131:10512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ainalea.com"] [uri "/.git/HEAD"] [unique_id "al6-eGQ0QHRwU3qTKYfWcwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:10:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:10:10.694192 2026] [security2:error] [pid 24822:tid 24822] [client 172.111.80.131:50456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.abeltours.com"] [uri "/.git/HEAD"] [unique_id "al5WcqS0tH9n5qWPYjdSNgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-20 00:07:36
(2 days ago)
Try to access /.git/config
Web App Attack
๐จ๐ญ
4server
2026-07-19 13:24:51
(3 days ago)
[SunJul1915:24:43.7558212026][security2:error][pid1233822:tid1234075][client172.111.80.131:0]ModSecu ...
show more
[SunJul1915:24:43.7558212026][security2:error][pid1233822:tid1234075][client172.111.80.131:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"filarmonicaagno.ch\"][uri\"/.git/HEAD\"][unique_id\"alzQG5FtiYrSukJn5YyzmAAAARI\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 04:40:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 00:40:43.438170 2026] [security2:error] [pid 1765494:tid 1765494] [client 172.111.80.131:29314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.starktigers75.com"] [uri "/.git/HEAD"] [unique_id "alxVSyDJfjYRurgyCg7JJwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 21:25:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 17:25:24.733407 2026] [security2:error] [pid 711757:tid 711757] [client 172.111.80.131:45824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.bigheartskitchen.net"] [uri "/.git/config"] [unique_id "alvvREHypgfJNkzSrXrSGgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 17:30:47
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 13:30:40.567227 2026] [security2:error] [pid 7345:tid 7345] [client 172.111.80.131:47050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.styxtake2.com"] [uri "/.git/config"] [unique_id "alpmwE167gwehcGQiy1w9AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 14:04:45
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 10:04:38.279696 2026] [security2:error] [pid 25445:tid 25445] [client 172.111.80.131:5760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.casatualiving.com"] [uri "/.git/config"] [unique_id "alo2dl-8wt3SepyP-bn1gQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 09:58:31
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 05:58:24.795537 2026] [security2:error] [pid 24054:tid 24054] [client 172.111.80.131:10060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mayflowersgifts.com"] [uri "/.git/config"] [unique_id "aln8wAxF1PzAGNsRYTzXLgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-17 05:55:04
(5 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 04:45:20
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 00:45:12.932217 2026] [security2:error] [pid 24263:tid 24344] [client 172.111.80.131:38280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dcsindo.com"] [uri "/.git/HEAD"] [unique_id "almzWINgJ_HKdsJeX33p9wAAAcw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 02:33:32
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 22:33:26.804795 2026] [security2:error] [pid 12187:tid 12187] [client 172.111.80.131:47542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgas.com"] [uri "/.git/HEAD"] [unique_id "almUdknSvSEL1Rk7t7xGPgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-16 11:09:01
(6 days ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,mx01,mx03]
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-16 10:08:02
(6 days ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack