๐บ๐ธ
TPI-Abuse
2026-10-08 15:20:36
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 11:20:30.543166 2026] [security2:error] [pid 19730:tid 19730] [client 172.68.151.97:11384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chiloiangallery.com.saadeh.ws"] [uri "/.git/config"] [unique_id "ase0vulZXLxa-_L0CUrv-QAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
arsonist
2026-10-06 18:47:33
(2 days ago)
[fail2ban]
2026-10-06T18:47:33.205806+00:00 arson caddy[1712]: {"level":"info","ts":1791312453.20577 ...
show more
[fail2ban]
2026-10-06T18:47:33.205806+00:00 arson caddy[1712]: {"level":"info","ts":1791312453.2057745,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"172.68.151.97","remote_port":"9854","client_ip":"172.68.151.97","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/@fs/src/.env?raw??","headers":{"User-Agent":["Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"Accept":["*/*"],"Cf-Ray":["a466d5d07a1b735b-CDG"],"X-Forwarded-Proto":["https"],"X-Forwarded-For":["35.241.163.27"],"X-Nextjs-Data":["1"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Cf-Ipcountry":["BE"],"Accept-Encoding":["gzip, br"],"Cdn-Loop":["cloudflare
...
show less
Bad Web Bot
๐ง๐ช
madeit
2026-10-05 12:17:27
(3 days ago)
Web App Attack
๐ต๐ฐ
sbk97 (https://sayor.net)
2026-10-04 07:42:20
(5 days ago)
SAYOR honeypot: observed attack /?file=/var/www/html/settings.php
Brute-Force
๐ซ๐ท
arsonist
2026-10-02 10:26:38
(1 week ago)
[fail2ban]
2026-10-02T10:26:37.964837+00:00 arson caddy[1890453]: {"level":"info","ts":1790936797.96 ...
show more
[fail2ban]
2026-10-02T10:26:37.964837+00:00 arson caddy[1890453]: {"level":"info","ts":1790936797.9648,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"172.68.151.97","remote_port":"12085","client_ip":"172.68.151.97","proto":"HTTP/2.0","method":"GET","host":"ayuworks.xyz","uri":"/wp-admin/","headers":{"X-Forwarded-For":["2001:41d0:367:29c::1"],"Cf-Connecting-Ip":["2001:41d0:367:29c::1"],"Cf-Visitor":["{\"scheme\":\"https\"}"],"Accept-Encoding":["gzip, br"],"Accept-Language":["en-US,en;q=0.9"],"Cf-Ray":["a443028b4da179d6-CDG"],"Cdn-Loop":["cloudflare; loops=1"],"X-Forwarded-Proto":["https"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"],"Cf-Ipcountry":["FR"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"]},"tls":{"resumed":false,"version":772,"cipher_suite"
...
show less
Bad Web Bot
Anonymous
2026-08-28 04:33:22
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-26 21:58:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 17:58:16.820686 2026] [security2:error] [pid 22765:tid 22765] [client 172.68.151.97:12674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rudiscreations.com"] [uri "/.git/config"] [unique_id "ao9heCqy1sEhpjWkwsjHcwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-26 11:47:54
(1 month ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.68.151.97 (FR/France/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.68.151.97 (FR/France/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 08:14:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:14:27.977949 2026] [security2:error] [pid 3721629:tid 3722075] [client 172.68.151.97:12887] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.allstartaxidermy.com"] [uri "/.git/HEAD"] [unique_id "ao6gY7ycJv2bkUkw0ARBDAAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 07:00:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:00:48.190048 2026] [security2:error] [pid 3948:tid 3974] [client 172.68.151.97:14231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "penboy7.com"] [uri "/.git/config"] [unique_id "ao6PIGGjIOvH4twvXtlpVwAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 12:52:26
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:52:21.562432 2026] [security2:error] [pid 18606:tid 18606] [client 172.68.151.97:11635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ontimelogistiks.com"] [uri "/.git/HEAD"] [unique_id "ao2QBTnIutx2DstzMXzfOwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 09:23:44
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:23:38.500482 2026] [security2:error] [pid 20734:tid 20734] [client 172.68.151.97:12381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.texastraumarecovery.com"] [uri "/.git/config"] [unique_id "ao1fGlcBx7x_exE69K5qXgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 07:20:44
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:20:39.276130 2026] [security2:error] [pid 13615:tid 13639] [client 172.68.151.97:10362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mouserart.com"] [uri "/.git/config"] [unique_id "aovwxyXxgFFGbRIZLxndMgAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 07:04:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:04:37.241848 2026] [security2:error] [pid 3058:tid 3058] [client 172.68.151.97:11028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.torahorah.royal-barbershop.com"] [uri "/.git/HEAD"] [unique_id "aovtBQSYnZs_InjhiiYo2QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 00:10:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 20:10:42.037124 2026] [security2:error] [pid 24232:tid 24232] [client 172.68.151.97:12189] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.inspiringindividualindustry.com"] [uri "/.git/config"] [unique_id "aouMAjMDR91RrUsqetNf3QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack