๐บ๐ธ
TPI-Abuse
2026-08-28 11:04:32
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:04:24.999138 2026] [security2:error] [pid 31436:tid 31436] [client 172.68.175.108:9731] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hotwheelguide.com"] [uri "/.git/config"] [unique_id "apFrONpAyj02TfkUsAzDQQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 00:05:11
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:05:06.259848 2026] [security2:error] [pid 30908:tid 30908] [client 172.68.175.108:11843] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.velocitymech.com"] [uri "/.git/HEAD"] [unique_id "apDQso9y0cdEEhf8uH8regAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:59:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:59:02.238104 2026] [security2:error] [pid 23411:tid 23428] [client 172.68.175.108:11980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.abroma.com"] [uri "/.git/HEAD"] [unique_id "apB65pdiOxTpuKB2E1JWuAAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:34:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:34:42.590726 2026] [security2:error] [pid 17482:tid 17482] [client 172.68.175.108:13441] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haddadpharmacy.com.saadeh.ws"] [uri "/.git/config"] [unique_id "apBnIipxK2DUduNZHHPXBQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:00:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:59:58.241363 2026] [security2:error] [pid 459:tid 459] [client 172.68.175.108:10799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bowerwood.com"] [uri "/.git/HEAD"] [unique_id "apBe_hli8jqaUE75GPYEuAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:26:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:26:18.648368 2026] [security2:error] [pid 13943:tid 13943] [client 172.68.175.108:10855] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.davidquiroa.com"] [uri "/.git/HEAD"] [unique_id "apAs6pexWeKoDw34HZPElgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 11:37:30
(1 day ago)
172.68.175.108 - - [27/Aug/2026:13:37:29 +0200] "GET /.git/config HTTP/1.1" 404 5476 "-" "Mozilla/5. ...
show more
172.68.175.108 - - [27/Aug/2026:13:37:29 +0200] "GET /.git/config HTTP/1.1" 404 5476 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-27 09:08:59
(1 day ago)
cloudlinux2 fail2ban: 2026-08-27 11:04:27,029 fail2ban.actions [1775]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-27 11:04:27,029 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Unban 93.57.249.128cloudlinux2 fail2ban: 2026-08-27 11:04:27,440 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 198.187.29.24 - 2026-08-27 11:04:27cloudlinux2 fail2ban: 2026-08-27 11:05:52,233 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 198.187.31.44 - 2026-08-27 11:05:51cloudlinux2 fail2ban: 2026-08-27 11:06:48,119 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 172.68.175.22 - 2026-08-27 11:06:48cloudlinux2 fail2ban: 2026-08-27 11:06:48,107 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 172.68.175.108 - 2026-08-27 11:06:47cloudlinux2 fail2ban: 2026-08-27 11:06:57,479 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 117.251.86.152 - 2026-08-27 11:06:57cloudlinux2 fail2ban: 2026-08-27 11:07:11,008 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 93.57.249.128 - 2026-08-27 11:07:10cloudlinux2 fail2ba
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 05:27:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 01:27:03.013974 2026] [security2:error] [pid 8997:tid 8997] [client 172.68.175.108:11930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lifeinsmoke.com"] [uri "/.git/config"] [unique_id "ao_Kp-Jg8Ha9Hb_zkIXhcwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 03:49:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:49:10.026347 2026] [security2:error] [pid 9675:tid 9675] [client 172.68.175.108:10147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "friendlyfarmforfun.daisydoesoap.com"] [uri "/.git/HEAD"] [unique_id "ao-zttNyG0WHidcgGdGY7AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 02:36:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 22:36:03.190567 2026] [security2:error] [pid 19649:tid 19649] [client 172.68.175.108:13284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.extreme-atv.com"] [uri "/.git/HEAD"] [unique_id "ao-ik5DcHh--PvMsyvfEAwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 02:02:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 22:02:38.601993 2026] [security2:error] [pid 4158:tid 4158] [client 172.68.175.108:9235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.homerbiz.com"] [uri "/.git/config"] [unique_id "ao-avpBMZqSl-NTOBH5pugAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Little Iguana
2026-08-26 23:42:09
(1 day ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-26 23:19:24
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.68.175.108 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:19:19.243255 2026] [security2:error] [pid 7168:tid 7168] [client 172.68.175.108:9292] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.psqeng.com"] [uri "/.git/HEAD"] [unique_id "ao90d0B60lfSHX_-a2CxywAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-26 22:00:39
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-26
Web App Attack
SSH
Hacking