๐บ๐ธ
TPI-Abuse
2026-08-22 14:05:36
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 10:05:30.424878 2026] [security2:error] [pid 15599:tid 15599] [client 172.68.151.48:13499] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mqyr.com"] [uri "/.git/HEAD"] [unique_id "aomsqk6OB53o_XKxGGT-0wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 12:52:05
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:51:59.713804 2026] [security2:error] [pid 7618:tid 7618] [client 172.68.151.48:9970] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "boraborapearlbookings.com"] [uri "/.git/config"] [unique_id "aombb_li9FyzayYJmHvTIgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 10:07:23
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:07:16.767926 2026] [security2:error] [pid 28589:tid 28589] [client 172.68.151.48:10571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atsfoundation.com.helpkccare.org"] [uri "/.git/config"] [unique_id "aol01MHnPDaQpb-hCqGknwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 01:25:37
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 21:25:28.201832 2026] [security2:error] [pid 30791:tid 30791] [client 172.68.151.48:12096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.belintxon.com"] [uri "/.git/HEAD"] [unique_id "aoj6iEho79gtY8fuXFZhDAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 20:18:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 16:17:59.129657 2026] [security2:error] [pid 2726:tid 2726] [client 172.68.151.48:13318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.luxurymicrobikinis.com"] [uri "/.git/HEAD"] [unique_id "aoiyd0Ep8yrkONRaQJyhbwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 18:36:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 14:36:49.097041 2026] [security2:error] [pid 21649:tid 21649] [client 172.68.151.48:10478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.unitedwestandent.org"] [uri "/.git/config"] [unique_id "aoiaweqbclapm8BQMUqC8gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-21 18:09:07
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
๐ฆ๐ฑ
router.al
2026-08-21 17:52:44
(1 day ago)
08/21/2026-17:52:44.165707 172.68.151.48 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple R ...
show more
08/21/2026-17:52:44.165707 172.68.151.48 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-21 01:39:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 21:39:49.111681 2026] [security2:error] [pid 10578:tid 10578] [client 172.68.151.48:12308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.citizensforsanity.com"] [uri "/.git/HEAD"] [unique_id "aoesZUgSL9MLgOmhXRYbPQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 16:05:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 12:05:22.402343 2026] [security2:error] [pid 12151:tid 12151] [client 172.68.151.48:14196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lapapevip.spyasociados.com"] [uri "/.git/HEAD"] [unique_id "aoclwsclFyRxHaeke0t7-AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 12:01:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 08:01:45.056290 2026] [security2:error] [pid 22995:tid 22995] [client 172.68.151.48:12142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.personalizedanniversarynapkins.com"] [uri "/.git/config"] [unique_id "aobsqYf0Wqfw_qfZ1pRMlwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 03:13:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 23:13:20.770041 2026] [security2:error] [pid 20327:tid 20327] [client 172.68.151.48:10012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.techsuite7.net"] [uri "/.git/config"] [unique_id "aoZw0EpLKSNqrReD9yUNGgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 01:15:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 21:15:51.477225 2026] [security2:error] [pid 8610:tid 8649] [client 172.68.151.48:12139] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.saskiarose.com"] [uri "/.git/config"] [unique_id "aoZVR6Kqh6O_FCFZf_LV2QAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-08-20 00:27:51
(3 days ago)
20/Aug/2026:02:27:50.351475 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
20/Aug/2026:02:27:50.351475 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.68.151.48] ModSecurity: Warning. Pattern match "^(?i:file|ftps?|https?):\\\\\\\\/\\\\\\\\/(?:\\\\\\\\d{1,3}\\\\\\\\.\\\\\\\\d{1,3}\\\\\\\\.\\\\\\\\d{1,3}\\\\\\\\.\\\\\\\\d{1,3})" at ARGS:dest. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf"] [line "56"] [id "931100"] [msg "Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address"] [data "Matched Data: http://169.254.169.254 found within ARGS:dest: http://169.254.169.254/latest/meta-data/iam/info"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-rfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/175/253"] [hostname "www.el-hacker.org"] [uri "/fetch"] [unique_id "aoZKBiamq6u7IaUhoEMQMwADmFA"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 02:42:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 22:42:24.241746 2026] [security2:error] [pid 15928:tid 15928] [client 172.68.151.48:11906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.advantstudio.com"] [uri "/.git/config"] [unique_id "aoUYEM5ix9ugzwF7UyVzlQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack