๐ณ๐ฑ
BlueWire Hosting
2026-08-28 07:09:38
(18 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:56:04
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:55:57.252558 2026] [security2:error] [pid 8027:tid 8027] [client 172.68.174.109:12696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.artspacecleveland.com"] [uri "/.git/HEAD"] [unique_id "apEi7WCNORvpxK8lRfBEcAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-28 00:50:50
(1 day ago)
[Fri Aug 28 10:50:49.420642 2026] [security2:error] [pid 583707] [client 172.68.174.109:14251] [clie ...
show more
[Fri Aug 28 10:50:49.420642 2026] [security2:error] [pid 583707] [client 172.68.174.109:14251] [client 172.68.174.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.stkildashule.org.au"] [uri "/.git/HEAD"] [unique_id "apDbadZTD77j25Ga9UkeOAAAAAM"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:59:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:59:38.013508 2026] [security2:error] [pid 6726:tid 6876] [client 172.68.174.109:11746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.seracon.com.ec"] [uri "/.git/HEAD"] [unique_id "apDPanoLyEPwlBKYarmheQAAAcM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 22:18:18
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 21:18:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:18:22.283107 2026] [security2:error] [pid 16698:tid 16698] [client 172.68.174.109:10809] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.psychicangelreader.com"] [uri "/.git/HEAD"] [unique_id "apCpnrCeR-yDtRYZs-0LqgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:22:15
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:22:09.076810 2026] [security2:error] [pid 2294:tid 2294] [client 172.68.174.109:9388] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "tv.freedrm.org"] [uri "/.git/config"] [unique_id "apCccYJoUjDNdVUhCAxl5AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:21:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:21:26.293905 2026] [security2:error] [pid 5484:tid 5484] [client 172.68.174.109:12066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cabanaconstructionandpaving.com"] [uri "/.git/HEAD"] [unique_id "apBV9o8iU9mA5QgDfyMD6AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
webko.si
2026-08-27 01:09:41
(2 days ago)
BARUTANA.si: Bruteforce web app access, URI detail: '/.git/config'.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 00:44:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 20:44:51.590275 2026] [security2:error] [pid 30473:tid 30473] [client 172.68.174.109:13971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.meridianranchdrc.org"] [uri "/.git/HEAD"] [unique_id "ao-Ig7Lva12ukc6BNdm5dgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 00:22:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 20:22:34.682764 2026] [security2:error] [pid 10307:tid 10307] [client 172.68.174.109:13460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thewillsmith.com"] [uri "/.git/HEAD"] [unique_id "ao-DStRHb5tQ-TFvYDi_0QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 17:38:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:38:06.730582 2026] [security2:error] [pid 9811:tid 9811] [client 172.68.174.109:14069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stricklinranch.com"] [uri "/.git/HEAD"] [unique_id "ao8kfq5AWx5EQTOXKod2AAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 14:44:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 10:44:10.961399 2026] [security2:error] [pid 15822:tid 15822] [client 172.68.174.109:12452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "basecampexp.com.smartstylehair.com"] [uri "/.git/config"] [unique_id "ao77usrAzHRapEeDR2R-vAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 11:54:25
(2 days ago)
GET /.git/HEAD HTTP/1.1
...
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-08-26 08:24:55
(2 days ago)
CMS/framework probe: 172.68.174.109 - - [26/Aug/2026:10:24:53 +0200] "GET /.git/HEAD HTTP/2.0" 301 1 ...
show more
CMS/framework probe: 172.68.174.109 - - [26/Aug/2026:10:24:53 +0200] "GET /.git/HEAD HTTP/2.0" 301 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36" asn=13335 org="Cloudflare, Inc." country=US
...
show less
Web App Attack