๐บ๐ธ
TPI-Abuse
2026-08-28 07:51:52
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:51:47.967905 2026] [security2:error] [pid 14580:tid 14580] [client 172.68.175.47:12627] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelpmcgrath.com"] [uri "/.git/config"] [unique_id "apE-E3Mu6Kh_ygV0j33P7gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-28 05:33:57
(23 hours ago)
cloudlinux2 fail2ban: 2026-08-28 07:30:11,448 fail2ban.filter [1478]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-28 07:30:11,448 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 180.153.236.16 - 2026-08-28 07:30:11cloudlinux2 fail2ban: 2026-08-28 07:30:23,777 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 27.49.19.47 - 2026-08-28 07:30:23cloudlinux2 fail2ban: 2026-08-28 07:31:17,096 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 27.49.19.47 - 2026-08-28 07:31:17cloudlinux2 fail2ban: 2026-08-28 07:31:27,789 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 27.49.19.47 - 2026-08-28 07:31:27cloudlinux2 fail2ban: 2026-08-28 07:31:27,897 fail2ban.filter [1478]: INFO [recidive] Found 27.49.19.47 - 2026-08-28 07:31:27cloudlinux2 fail2ban: 2026-08-28 07:31:27,893 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Ban 27.49.19.47cloudlinux2 fail2ban: 2026-08-28 07:31:42,219 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 223.181.121.54 - 2026-08-28 07:31:42cloudlinux2 fail2ban: 2026-08-28 07:
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 04:16:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:16:10.961401 2026] [security2:error] [pid 31624:tid 31665] [client 172.68.175.47:11971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "velatorioslucenses.soluciona.biz"] [uri "/.git/config"] [unique_id "apELilDulYMIkIX4OK-NJwAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-28 00:56:01
(1 day ago)
[FriAug2802:55:55.9554062026][security2:error][pid1940994:tid1941048][client172.68.175.47:0]ModSecur ...
show more
[FriAug2802:55:55.9554062026][security2:error][pid1940994:tid1941048][client172.68.175.47:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.kvsm-blackstone.com\"][uri\"/.git/config\"][unique_id\"apDcm1ug0Rx9fnTVlsvUnQAAAFM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:01:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:01:17.230713 2026] [security2:error] [pid 1340:tid 1340] [client 172.68.175.47:12332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.medusakenya.com"] [uri "/.git/config"] [unique_id "apB7bev3KVKQCFx_1T3JmAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:45:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:45:31.618677 2026] [security2:error] [pid 17212:tid 17212] [client 172.68.175.47:12062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "konstantiasofokleous.com"] [uri "/.git/HEAD"] [unique_id "apB3u1KY3ocwScdyrcxbHAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 07:13:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 03:12:55.697570 2026] [security2:error] [pid 20889:tid 20889] [client 172.68.175.47:10470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.alexsource.com"] [uri "/.git/HEAD"] [unique_id "ao_jd-KHyTtbXFQexG6a4wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 05:26:37
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 04:53:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:53:17.271098 2026] [security2:error] [pid 8124:tid 8124] [client 172.68.175.47:13961] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sinko-intl.com"] [uri "/.git/HEAD"] [unique_id "ao_CvUpCz9bXEfqq4VhWUwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 00:05:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 20:05:50.929972 2026] [security2:error] [pid 30904:tid 30904] [client 172.68.175.47:13640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mbehel.com"] [uri "/.git/config"] [unique_id "ao9_Xl_aBJo3FDdhkopwgAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 23:46:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:46:09.181454 2026] [security2:error] [pid 25862:tid 25862] [client 172.68.175.47:13904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cathayexpress.com.dragoldio.com"] [uri "/.git/config"] [unique_id "ao96wdjQvXVW4Q4KvwmNSQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 21:45:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 17:44:55.830073 2026] [security2:error] [pid 8781:tid 8781] [client 172.68.175.47:10129] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sabras.com"] [uri "/.git/HEAD"] [unique_id "ao9eV8Nf1LmKAMfT7dDqzQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 20:52:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 16:51:59.628120 2026] [security2:error] [pid 21580:tid 21592] [client 172.68.175.47:12540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.forestancestry.com"] [uri "/.git/config"] [unique_id "ao9R70tux3OQnHbadaMb8AAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 17:39:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:39:43.880834 2026] [security2:error] [pid 21622:tid 21622] [client 172.68.175.47:12044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.purplebikinis.com"] [uri "/.git/config"] [unique_id "ao8k31K_7g5qktJWuTjXRAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 16:41:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:41:04.863650 2026] [security2:error] [pid 13571:tid 13571] [client 172.68.175.47:12219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.northernlightsbev.com"] [uri "/.git/config"] [unique_id "ao8XIMYSJf26I7Epjb314gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack