๐ฉ๐ช
raph
2026-07-21 22:51:53
(1 hour ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 17:48:31
(6 hours ago)
2026/07/21 16:09:10 [error] 4736#4736: *96020 [client 172.111.91.69] ModSecurity: Access denied with ...
show more
2026/07/21 16:09:10 [error] 4736#4736: *96020 [client 172.111.91.69] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.28.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "appwrite.ingeltechgh.com"] [uri "/.git/HEAD"] [unique_id "178465015054.947040"] [ref ""], client: 172.111.91.69, server: srv.ingeltechgh.com, request: "GET /.git/HEAD HTTP/1.1", host: "appwrite.ingeltechgh.com"
2026/07/21 17:48:28 [error] 4713#4713: *98638 [client 172.111.91.69] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/loc
...
show less
Brute-Force
๐บ๐ธ
MPL
2026-07-21 17:31:23
(6 hours ago)
tcp/443
Port Scan
๐บ๐ธ
MPL
2026-07-21 16:11:08
(8 hours ago)
tcp/443 (2 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-21 15:00:17
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 11:00:11.743467 2026] [security2:error] [pid 17048:tid 17048] [client 172.111.91.69:11138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.angove.biz"] [uri "/.git/HEAD"] [unique_id "al-Je9LK3DfXyzhYEfP8wgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:22:59
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:22:55.117280 2026] [security2:error] [pid 3432776:tid 3432776] [client 172.111.91.69:21764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.radiointernational.net"] [uri "/.git/HEAD"] [unique_id "al9kn9DYkw-sGwR9h8C6WAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:27:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:27:14.678082 2026] [security2:error] [pid 18337:tid 18337] [client 172.111.91.69:55958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "partybussantafe.com"] [uri "/.git/HEAD"] [unique_id "al6u0gOj2EiisQ531KI7lQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2026-07-20 23:20:06
(1 day ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 22:59:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 18:59:00.936419 2026] [security2:error] [pid 2718490:tid 2718507] [client 172.111.91.69:63556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.aapm.eu"] [uri "/.git/HEAD"] [unique_id "al6oNKr4qP8BO4UgTwncKwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 19:08:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 15:08:00.153772 2026] [security2:error] [pid 6869:tid 6869] [client 172.111.91.69:14842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oliver.pattenden.com"] [uri "/.git/HEAD"] [unique_id "al5yEDPK_dEBX7juQjtSwAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 18:29:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 14:29:06.366567 2026] [security2:error] [pid 24823:tid 24823] [client 172.111.91.69:48220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.weddingsuppliescanada.com"] [uri "/.git/HEAD"] [unique_id "al5o8inU6RK5eLL4NxHDtwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:58:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:58:14.229093 2026] [security2:error] [pid 32060:tid 32125] [client 172.111.91.69:22308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.isoceansl.com"] [uri "/.git/HEAD"] [unique_id "al5htkOkBp_m8eaQ8JOmqQAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:42:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:42:09.121214 2026] [security2:error] [pid 28931:tid 28931] [client 172.111.91.69:52392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cyberrob.net"] [uri "/.git/HEAD"] [unique_id "al5d8W1tZBjKjbd6qWaovgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-20 17:18:33
(1 day ago)
Try to access /.git/HEAD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:05:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:04:59.418710 2026] [security2:error] [pid 13266:tid 13266] [client 172.111.91.69:54286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.oshadega.com"] [uri "/.git/HEAD"] [unique_id "al5VO5WznJkWh8aElu-snQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack