πΊπΈ
TPI-Abuse
2026-08-22 10:40:38
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:40:31.957334 2026] [security2:error] [pid 4726:tid 4726] [client 172.68.174.246:11751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rentaroller.com.au"] [uri "/.git/config"] [unique_id "aol8n21fzaBSTU0FoweFpAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
paulshipley.com.au
2026-08-22 10:04:26
(5 hours ago)
[Sat Aug 22 20:04:25.563784 2026] [security2:error] [pid 257407] [client 172.68.174.246:14033] [clie ...
show more
[Sat Aug 22 20:04:25.563784 2026] [security2:error] [pid 257407] [client 172.68.174.246:14033] [client 172.68.174.246] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "talentaymerch.com.au"] [uri "/.git/config"] [unique_id "aol0KUeRUHfDtiNvgS03lAAAAAg"]
...
show less
Web App Attack
Anonymous
2026-08-22 07:31:19
(8 hours ago)
172.68.174.246 - - [22/Aug/2026:07:31:19 +0000] "GET /.git/config HTTP/1.1" 404 4404 "-" "Mozilla/5. ...
show more
172.68.174.246 - - [22/Aug/2026:07:31:19 +0000] "GET /.git/config HTTP/1.1" 404 4404 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π«π·
Lino Project
2026-08-22 05:44:11
(10 hours ago)
172.68.174.246 - - [22/Aug/2026:07:44:10 +0200] "GET /.git/config HTTP/1.1" 302 5818 "-" "Mozilla/5. ...
show more
172.68.174.246 - - [22/Aug/2026:07:44:10 +0200] "GET /.git/config HTTP/1.1" 302 5818 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
172.68.174.246 - - [22/Aug/2026:07:44:10 +0200] "GET /.git/HEAD HTTP/1.1" 302 5818 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Lino Project
2026-08-22 05:24:00
(10 hours ago)
172.68.174.246 - - [22/Aug/2026:07:23:59 +0200] "GET /.git/HEAD HTTP/2.0" 403 385 "-" "Mozilla/5.0 ( ...
show more
172.68.174.246 - - [22/Aug/2026:07:23:59 +0200] "GET /.git/HEAD HTTP/2.0" 403 385 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
ALPHANET
2026-08-21 04:19:09
(1 day ago)
web exploits
Hacking
Exploited Host
Web App Attack
π¨π
4server
2026-08-21 02:49:33
(1 day ago)
[FriAug2104:49:28.3617912026][security2:error][pid3767422:tid3767886][client172.68.174.246:0]ModSecu ...
show more
[FriAug2104:49:28.3617912026][security2:error][pid3767422:tid3767886][client172.68.174.246:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"465\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"aidweb.ch\"][uri\"/.git/config\"][unique_id\"aoe8uEpy7WYgUIgz12n3HAAAABI\"]
show less
Hacking
Web App Attack
π³π΄
jad-abuse
2026-08-20 06:29:58
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 03:21:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 23:21:26.298613 2026] [security2:error] [pid 17209:tid 17209] [client 172.68.174.246:13443] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.elpais.mx"] [uri "/.git/config"] [unique_id "aoZyttSKt1ZuZW3ifNQGBQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 00:31:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:31:47.363973 2026] [security2:error] [pid 24527:tid 24556] [client 172.68.174.246:10351] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internationalacademyoffinancialmanagement.com.aafm.us"] [uri "/.git/HEAD"] [unique_id "aoZK81r5ysIUoByrKv8H9gAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-19 21:26:40
(2 days ago)
[20/Aug/2026:00:26:40 +0300] -- 172.68.174.246 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[20/Aug/2026:00:26:40 +0300] -- 172.68.174.246 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-19 18:26:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 14:26:39.531664 2026] [security2:error] [pid 28245:tid 28245] [client 172.68.174.246:13304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oposicionesyconcursos.es"] [uri "/.git/HEAD"] [unique_id "aoX1Xw95dJrXxQpQRNsvagAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-19 16:45:09
(2 days ago)
GET /.git/config HTTP/1.1
...
Web App Attack
πΊπΈ
freeutka
2026-05-06 13:30:12
(3 months ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
πΊπΈ
mawan
2025-10-06 00:02:54
(10 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack