๐ฆ๐บ
paulshipley.com.au
2026-08-20 05:50:18
(1 day ago)
[Thu Aug 20 15:50:17.279236 2026] [security2:error] [pid 449063] [client 172.68.174.171:12352] [clie ...
show more
[Thu Aug 20 15:50:17.279236 2026] [security2:error] [pid 449063] [client 172.68.174.171:12352] [client 172.68.174.171] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.co.nz"] [uri "/.git/config"] [unique_id "aoaVmehWOssGKDmQeMaoLQAAAAE"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:56:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.171 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:56:05.960763 2026] [security2:error] [pid 17461:tid 17461] [client 172.68.174.171:9489] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.chatsupply.us"] [uri "/.git/HEAD"] [unique_id "aoZQpam7OOQGupZeD7tE2QAAAHg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:35:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.171 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:35:35.516644 2026] [security2:error] [pid 6851:tid 6864] [client 172.68.174.171:12642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lifecoachcertified.aafm.us"] [uri "/.git/config"] [unique_id "aoZL17H1JTzxbHJ6DACcUQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-19 21:04:43
(1 day ago)
[20/Aug/2026:00:04:42 +0300] -- 172.68.174.171 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[20/Aug/2026:00:04:42 +0300] -- 172.68.174.171 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-08-19 16:51:42
(1 day ago)
Probing for .git:
172.68.174.171 - - [19/Aug/2026:18:50:31 +0200] "GET /.git/HEAD HTTP/2.0" 403 548 ...
show more
Probing for .git:
172.68.174.171 - - [19/Aug/2026:18:50:31 +0200] "GET /.git/HEAD HTTP/2.0" 403 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
webko.si
2026-08-19 09:15:29
(1 day ago)
BARUTANA.si: Bruteforce web app access, URI detail: '/.git/HEAD'.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 08:50:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.171 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 04:50:33.629959 2026] [security2:error] [pid 9017:tid 9017] [client 172.68.174.171:13590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grieve.tv"] [uri "/.git/HEAD"] [unique_id "aoVuWZ9yUG_dy_M71xYYhAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 06:15:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.171 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 02:15:08.818112 2026] [security2:error] [pid 18194:tid 18194] [client 172.68.174.171:9442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saadeh.ws"] [uri "/.git/HEAD"] [unique_id "aoVJ7Hzr7sgvaaWkBGr1rgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-11 16:57:01
(3 months ago)
[Mon May 11 18:57:00.715066 2026] [authz_core:error] [pid 7123] [client 172.68.174.171:9722] AH01630 ...
show more
[Mon May 11 18:57:00.715066 2026] [authz_core:error] [pid 7123] [client 172.68.174.171:9722] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon May 11 18:57:00.926455 2026] [authz_core:error] [pid 7123] [client 172.68.174.171:9722] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon May 11 18:57:01.138019 2026] [authz_core:error] [pid 7123] [client 172.68.174.171:9722] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-02-27 01:37:39
(5 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฏ๐ต
S.O.B.A. Dev.
2025-11-29 11:06:07
(8 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ณ๐ฑ
Study Bitcoin ๐ค
2024-12-18 07:54:37
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2024-12-15 07:16:40
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2024-12-15 00:00:38
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 05:29:54
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 172.68.174.171 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.68.174.171 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 01:29:47.994741 2024] [security2:error] [pid 10917:tid 10917] [client 172.68.174.171:36466] [client 172.68.174.171] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.ard.global|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.ard.global"] [uri "/em3YkWr3.bak"] [unique_id "ZsGGyyw4PwJUZoXojPIK4AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack