Anonymous
2026-07-22 12:14:47
(5 hours ago)
2026/07/22 12:10:39 [error] 4721#4721: *111699 [client 172.111.97.7] ModSecurity: Access denied with ...
show more
2026/07/22 12:10:39 [error] 4721#4721: *111699 [client 172.111.97.7] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.28.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "abii-reporting.ingeltechgh.com"] [uri "/.git/HEAD"] [unique_id "178472223919.373288"] [ref ""], client: 172.111.97.7, server: srv.ingeltechgh.com, request: "GET /.git/HEAD HTTP/1.1", host: "abii-reporting.ingeltechgh.com"
2026/07/22 12:10:40 [error] 4721#4721: *111699 [client 172.111.97.7] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [fil
...
show less
Brute-Force
Anonymous
2026-07-22 11:40:02
(5 hours ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
MM-bot
2026-07-21 19:47:48
(21 hours ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-07-21 21:47:48 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-21 19:30:36
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 15:30:28.198574 2026] [security2:error] [pid 11735:tid 11735] [client 172.111.97.7:3922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rockinr.org"] [uri "/.git/config"] [unique_id "al_I1ErRbUxLZ-Dd_30LCwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 14:09:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 10:09:32.232188 2026] [security2:error] [pid 19277:tid 19277] [client 172.111.97.7:59128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kln.ne.jp"] [uri "/.git/HEAD"] [unique_id "al99nEzS7kjN92EaI8QF0wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 13:52:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 09:52:11.445561 2026] [security2:error] [pid 3304361:tid 3304361] [client 172.111.97.7:17930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.willowbrookins.com"] [uri "/.git/HEAD"] [unique_id "al95i8Y6nROWR8PYaLNmEQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:54:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:54:04.472750 2026] [security2:error] [pid 270843:tid 270843] [client 172.111.97.7:41386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clcmillvale.com"] [uri "/.git/HEAD"] [unique_id "al9r7OuSOEE3l2Y-1t6CjAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:05:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:04:58.335343 2026] [security2:error] [pid 380216:tid 380216] [client 172.111.97.7:49862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tortoisehosting.com"] [uri "/.git/HEAD"] [unique_id "al9gaieCmOr98AYd06MKlgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 11:39:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:39:53.401116 2026] [security2:error] [pid 278054:tid 278054] [client 172.111.97.7:10874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.guardmagic.com"] [uri "/.git/HEAD"] [unique_id "al9aiW4gjiRrnZzLIa4XCwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-21 10:08:13
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 172.111.97.7 - - [21/Jul/2026:13:08:12 +0300] "GE ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 172.111.97.7 - - [21/Jul/2026:13:08:12 +0300] "GET /.git/HEAD HTTP/1.1" 404 808 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 00:39:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:39:24.861698 2026] [security2:error] [pid 3836320:tid 3836320] [client 172.111.97.7:45726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.title34.com"] [uri "/.git/HEAD"] [unique_id "al6_vHryLIwgc3vDrPDoVAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:52:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:52:38.318509 2026] [security2:error] [pid 27859:tid 27859] [client 172.111.97.7:47462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kitebeach.com"] [uri "/.git/HEAD"] [unique_id "al60xtP6JlbTDGHC546TqwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:18:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:18:15.573044 2026] [security2:error] [pid 10285:tid 10285] [client 172.111.97.7:55594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.buildyourownpublishing.banis-associates.com"] [uri "/.git/HEAD"] [unique_id "al6st7poQTLDBePVZOtryQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 22:28:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 18:28:16.597344 2026] [security2:error] [pid 21956:tid 21956] [client 172.111.97.7:42172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dawnmazur.com"] [uri "/.git/HEAD"] [unique_id "al6hANpZ7VP_gxmsWnlniAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:56:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.97.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:56:00.749203 2026] [security2:error] [pid 2334793:tid 2335179] [client 172.111.97.7:32222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coloradospringsmardigras.com"] [uri "/.git/HEAD"] [unique_id "al5hMFH--6jQKVXgvhD8rQAAAsk"]
show less
Brute-Force
Bad Web Bot
Web App Attack