πΊπΈ
TPI-Abuse
2026-08-26 02:58:51
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:58:47.328854 2026] [security2:error] [pid 1056:tid 1056] [client 172.68.151.49:12351] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jerryfeil.com"] [uri "/.git/config"] [unique_id "ao5WZ-A3dGCbPrEbWCiXeAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Blexyel
2026-08-25 22:54:55
(18 hours ago)
172.68.151.49 - - [26/Aug/2026:00:54:54 +0200] "GET /.git/config HTTP/1.1" 404 13 "-" "Mozilla/5.0 ( ...
show more
172.68.151.49 - - [26/Aug/2026:00:54:54 +0200] "GET /.git/config HTTP/1.1" 404 13 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 17:22:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 13:22:07.909183 2026] [security2:error] [pid 23052:tid 23052] [client 172.68.151.49:12701] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nmorganist.org"] [uri "/.git/HEAD"] [unique_id "ao3PP-pTabtTGxMOuO9GegAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 16:54:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 12:54:27.971746 2026] [security2:error] [pid 17106:tid 17106] [client 172.68.151.49:9663] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.carolinapetportraits.com"] [uri "/.git/HEAD"] [unique_id "ao3Iw2MB0rzDJuaid3tk9QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-08-25 14:24:47
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 02:22:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 22:22:01.741345 2026] [security2:error] [pid 29810:tid 29810] [client 172.68.151.49:11123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.torahorah.com"] [uri "/.git/config"] [unique_id "aoz8SaQetL4ZMH8XLMpe1QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-08-24 19:01:36
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π¬π§
openstrike.co.uk
2026-08-24 05:14:05
(2 days ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
π©πͺ
Jochen Pretli
2026-08-24 04:08:43
(2 days ago)
connection to honeypot
Email Spam
Port Scan
πΊπΈ
TPI-Abuse
2026-08-23 03:20:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 23:20:15.284565 2026] [security2:error] [pid 20552:tid 20552] [client 172.68.151.49:12207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doreenkimura.com"] [uri "/.git/HEAD"] [unique_id "aopm768DU6EHhR4KtDg3cwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alboweb B.V.
2026-08-22 20:11:02
(3 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 13:30:59
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:30:52.734866 2026] [security2:error] [pid 11797:tid 11797] [client 172.68.151.49:10157] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southernreader.com"] [uri "/.git/config"] [unique_id "aomkjFqQONEpHAlOoskNwQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 08:15:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 04:14:55.532733 2026] [security2:error] [pid 13039:tid 13039] [client 172.68.151.49:13390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.constructionloansfunding.com"] [uri "/.git/HEAD"] [unique_id "aolaf_Zqwe4aElxxWXORLQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 01:39:56
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 21:39:49.111644 2026] [security2:error] [pid 9978:tid 9978] [client 172.68.151.49:9411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.citizensforsanity.com"] [uri "/.git/config"] [unique_id "aoesZePt8g6LkVy8DwzUsAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-20 22:01:06
(5 days ago)
Auto-ban: >3000 req/min op 2026-08-20
Web App Attack
SSH
Hacking