๐บ๐ธ
TPI-Abuse
2026-08-25 06:21:50
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 02:21:43.863900 2026] [security2:error] [pid 10963:tid 10963] [client 172.68.174.9:10431] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.orchestrateyouraptitudes.com"] [uri "/.git/HEAD"] [unique_id "ao00d-9atTLphxjEVSetBgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 03:13:37
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 23:13:33.220401 2026] [security2:error] [pid 17877:tid 17877] [client 172.68.174.9:11543] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hygeiamedical.icu"] [uri "/.git/config"] [unique_id "ao0IXbptiAVeanF7378oDAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-08-25 03:10:36
(5 hours ago)
Probing for .git:
172.68.174.9 - - [25/Aug/2026:05:10:35 +0200] "GET /.git/HEAD HTTP/2.0" 403 548 "- ...
show more
Probing for .git:
172.68.174.9 - - [25/Aug/2026:05:10:35 +0200] "GET /.git/HEAD HTTP/2.0" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 09:55:32
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 05:55:26.904897 2026] [security2:error] [pid 20616:tid 20616] [client 172.68.174.9:10780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.marjorierosenberg.com"] [uri "/.git/config"] [unique_id "aowVDp-pnMiOfvdz5KqG5QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 04:40:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:40:22.413895 2026] [security2:error] [pid 23992:tid 23992] [client 172.68.174.9:13042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.castlerental.net"] [uri "/.git/config"] [unique_id "aovLNtFN6ETcfvEFOc2nIwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-21 00:22:11
(4 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 17:25:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 13:25:17.983995 2026] [security2:error] [pid 22259:tid 22259] [client 172.68.174.9:9678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.h2ofall.co"] [uri "/.git/config"] [unique_id "aoc4ffnvxeUSCc2-EFVepQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-20 06:42:34
(5 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:56:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:56:27.845244 2026] [security2:error] [pid 27948:tid 27955] [client 172.68.174.9:10721] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.managementconsultant.us"] [uri "/.git/config"] [unique_id "aoZQu7sVzcYke7HPEhmnZQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:17:24
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:17:19.519085 2026] [security2:error] [pid 27186:tid 27186] [client 172.68.174.9:13272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bccnews.us"] [uri "/.git/HEAD"] [unique_id "aoZHj2O0aWjR-hoJ3Np38AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 22:17:23
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 18:17:16.134932 2026] [security2:error] [pid 3732:tid 3732] [client 172.68.174.9:12480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.manoli.cl"] [uri "/.git/HEAD"] [unique_id "aoYrbC6S94MBF0NGRVbvFAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wimaxnz
2026-05-11 07:19:23
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐ฟ๐ฆ
agentics
2025-11-21 00:47:01
(9 months ago)
172.68.174.9 report :
DDoS Attack
FTP Brute-Force
Port Scan
Hacking
Spoofing
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-05-01 15:12:20
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 172.68.174.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 01 11:12:13.627438 2025] [security2:error] [pid 540257:tid 540257] [client 172.68.174.9:17374] [client 172.68.174.9] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newmanwood.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newmanwood.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBOPTT6HBGKTDnDZ8zxtxQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-04-16 02:08:42
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack