π©πͺ
FeG Deutschland
2026-08-23 07:16:28
(6 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
π©πͺ
4server
2026-08-21 02:49:37
(2 days ago)
[FriAug2104:49:33.6503342026][security2:error][pid478723:tid478969][client172.68.174.195:0]ModSecuri ...
show more
[FriAug2104:49:33.6503342026][security2:error][pid478723:tid478969][client172.68.174.195:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.agilityrossoblu.ch\"][uri\"/.git/HEAD\"][unique_id\"aoe8ve45xC0lLothAKq_rAAAAgA\"]
show less
Port Scan
Brute-Force
Web App Attack
π§πͺ
madeit
2026-08-21 01:33:06
(2 days ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 20:24:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 16:24:18.431287 2026] [security2:error] [pid 13785:tid 13785] [client 172.68.174.195:10860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evolute.io"] [uri "/.git/HEAD"] [unique_id "aodicj2NtDktaUG22VlsSQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-08-20 15:14:55
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-08-20 14:50:51
(2 days ago)
172.68.174.195 pi.patrz.eu - [20/Aug/2026:16:50:45 +0200] "GET /.git/config HTTP/2.0" 404 1116 "-" " ...
show more
172.68.174.195 pi.patrz.eu - [20/Aug/2026:16:50:45 +0200] "GET /.git/config HTTP/2.0" 404 1116 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 10:32:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 06:32:01.753678 2026] [security2:error] [pid 583:tid 583] [client 172.68.174.195:10409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.escribaniasmith.com.ar"] [uri "/.git/HEAD"] [unique_id "aobXoaJXw8-nsbLp8HnRhAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
iNetWorker
2026-08-20 09:44:24
(3 days ago)
trolling for resource vulnerabilities
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 03:15:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 23:15:01.269198 2026] [security2:error] [pid 20045:tid 20045] [client 172.68.174.195:11712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.juca.com.mx"] [uri "/.git/config"] [unique_id "aoZxNT3dP0zpijJ6BbetzgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 00:55:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:55:04.670428 2026] [security2:error] [pid 12287:tid 12287] [client 172.68.174.195:13948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.alphacom.us"] [uri "/.git/HEAD"] [unique_id "aoZQaETxC-RTMthwomItlQAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 00:34:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:33:55.458173 2026] [security2:error] [pid 10894:tid 10894] [client 172.68.174.195:9875] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "janner.janner.us"] [uri "/.git/config"] [unique_id "aoZLcwyChG3Ix-vtvCSzyAAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-19 21:23:42
(3 days ago)
[20/Aug/2026:00:23:42 +0300] -- 172.68.174.195 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[20/Aug/2026:00:23:42 +0300] -- 172.68.174.195 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
π·π΄
clauss
2026-08-19 20:21:59
(3 days ago)
172.68.174.195 - - [19/Aug/2026:23:21:59 +0300] "GET /.git/HEAD HTTP/2.0" 403 273 "-" "Mozilla/5.0 ( ...
show more
172.68.174.195 - - [19/Aug/2026:23:21:59 +0300] "GET /.git/HEAD HTTP/2.0" 403 273 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
172.68.174.195 - - [19/Aug/2026:23:21:59 +0300] "GET /.git/config HTTP/2.0" 403 273 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-19 17:58:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 13:58:53.433399 2026] [security2:error] [pid 20366:tid 20394] [client 172.68.174.195:13353] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indigocapital.es"] [uri "/.git/config"] [unique_id "aoXu3VGO-kT-y4IzFytHkgAAAY4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-19 07:32:59
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 03:32:54.915124 2026] [security2:error] [pid 26713:tid 26774] [client 172.68.174.195:12870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gemini.pe"] [uri "/.git/HEAD"] [unique_id "aoVcJnhhTVJ6pXpv7XBKWAAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack