๐ณ๐ฑ
BlueWire Hosting
2026-08-28 07:09:37
(13 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:44:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:44:09.372198 2026] [security2:error] [pid 17094:tid 17100] [client 172.68.174.128:11481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tierrasolymar.com"] [uri "/.git/HEAD"] [unique_id "apCFeQ4b1XwjxOq1IHU_8wAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:41:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:40:57.524266 2026] [security2:error] [pid 13254:tid 13254] [client 172.68.174.128:11343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.canfieldnyc.com"] [uri "/.git/HEAD"] [unique_id "apBaifjkz__EmFUvQMSDBQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:48:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:48:30.300002 2026] [security2:error] [pid 1933:tid 1933] [client 172.68.174.128:13429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.disenowebprofesional.com"] [uri "/.git/config"] [unique_id "apBALg6lQTn1DMuucs15MgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:01:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:01:49.568232 2026] [security2:error] [pid 28230:tid 28230] [client 172.68.174.128:9781] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.murciafm.murciafm.com"] [uri "/.git/HEAD"] [unique_id "apAnLQkwCOVdOZ5mXVisBQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 05:37:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 01:37:35.062766 2026] [security2:error] [pid 15197:tid 15197] [client 172.68.174.128:9458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.geckoturner.com"] [uri "/.git/config"] [unique_id "ao_NH59390mDJOW8YJU5_AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 01:09:16
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 20:45:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 16:45:37.067714 2026] [security2:error] [pid 4771:tid 4771] [client 172.68.174.128:9688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "advmach.com"] [uri "/.git/config"] [unique_id "ao9QccH10ObputS8o25cOAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
filou812
2026-08-26 19:28:48
(2 days ago)
url tried is "/.git/config"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 16:43:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:43:47.274169 2026] [security2:error] [pid 8002:tid 8002] [client 172.68.174.128:9362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.yoshiyukiya.com"] [uri "/.git/config"] [unique_id "ao8Xw5exuBw-lX-Ok8X3qAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-08-26 04:59:46
(2 days ago)
172.68.174.128 - - [25/Aug/2026:22:59:45 -0600] "GET /.git/config HTTP/2.0" 301 390 "-" "Mozilla/5.0 ...
show more
172.68.174.128 - - [25/Aug/2026:22:59:45 -0600] "GET /.git/config HTTP/2.0" 301 390 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 04:51:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 00:50:58.217078 2026] [security2:error] [pid 25154:tid 25154] [client 172.68.174.128:10569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "copierswilmington.computersraleigh.com"] [uri "/.git/config"] [unique_id "ao5wsosgbGCFr1NV_NbNcQAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 04:07:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 00:07:38.991609 2026] [security2:error] [pid 10687:tid 10687] [client 172.68.174.128:13471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.stkm.com"] [uri "/.git/HEAD"] [unique_id "ao5miq398oKtcG-_H91mFwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-25 21:59:48
(2 days ago)
Auto-ban: >3000 req/min op 2026-08-25
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-25 15:42:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 11:42:14.662430 2026] [security2:error] [pid 23693:tid 23693] [client 172.68.174.128:13411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ontimelogistiks.com"] [uri "/.git/config"] [unique_id "ao231jtYduu9yWtWqhPPvQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack