๐บ๐ธ
TPI-Abuse
2026-07-21 18:06:44
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:06:41.636271 2026] [security2:error] [pid 2229450:tid 2229450] [client 172.111.91.36:7104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lambert-heating-and-air.com"] [uri "/.git/HEAD"] [unique_id "al-1MRv4bZ-wpoTeZ50NGgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 11:08:06
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:07:59.242249 2026] [security2:error] [pid 31984:tid 31984] [client 172.111.91.36:62290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jonesypop.com"] [uri "/.git/HEAD"] [unique_id "al9TD30oKIf05KPDnXv1IwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 10:01:58
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 06:01:55.037752 2026] [security2:error] [pid 28350:tid 28350] [client 172.111.91.36:45256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.maritanasystems.eckerberg.net"] [uri "/.git/HEAD"] [unique_id "al9Dk6SJ-aYEr1yLrXeKogAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 08:59:34
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 04:59:29.560254 2026] [security2:error] [pid 3232:tid 3232] [client 172.111.91.36:36574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jeffgambill.com"] [uri "/.git/HEAD"] [unique_id "al808cJOr13-n3Y7fFPVZAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 00:05:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:05:02.257684 2026] [security2:error] [pid 2853980:tid 2854006] [client 172.111.91.36:19544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nabsci.com"] [uri "/.git/HEAD"] [unique_id "al63rua4iaUTLAqeZvhzTAAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:28:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:28:08.290683 2026] [security2:error] [pid 9977:tid 9977] [client 172.111.91.36:24672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hshs82.com"] [uri "/.git/HEAD"] [unique_id "al5aqNQvkI_k2NyRgmAuZQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:04:02
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:03:56.440283 2026] [security2:error] [pid 3248996:tid 3248996] [client 172.111.91.36:22802] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "autodiscover.tapwagon305.com"] [uri "/.git/HEAD"] [unique_id "al5U_NI3R0VMaIHGYKayrAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 12:41:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 08:41:21.504840 2026] [security2:error] [pid 20510:tid 20510] [client 172.111.91.36:13870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.keithwillwynne.com"] [uri "/.git/config"] [unique_id "al4XcW5Devg5Myq4kpyDswAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 03:34:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 23:34:52.437517 2026] [security2:error] [pid 30803:tid 30803] [client 172.111.91.36:37390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.buenasfrecuencias.com"] [uri "/.git/config"] [unique_id "alxF3IjsZFW-NFTlYAsryQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-19 02:21:13
(2 days ago)
Try to access /.git/config
Web App Attack
๐ฌ๐ง
Oakley
2026-07-18 19:41:25
(3 days ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-03 11:48:12
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.111.91.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 06:48:09.011287 2026] [security2:error] [pid 22195:tid 22195] [client 172.111.91.36:20894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thelotsmokehouse.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thelotsmokehouse.com"] [uri "/debug/.log"] [unique_id "aabKeay2tTVsDCP5qCvQ3QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack