๐บ๐ธ
TPI-Abuse
2026-08-24 06:43:28
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 02:43:22.114444 2026] [security2:error] [pid 15350:tid 15350] [client 172.68.175.72:12349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.polarisled.com"] [uri "/.git/config"] [unique_id "aovoCjX1CH_x4E6bt88IbAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 05:19:39
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 01:19:33.073075 2026] [security2:error] [pid 32136:tid 32136] [client 172.68.175.72:12205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.frequencyrecordsllc.com.theavgroup.com"] [uri "/.git/HEAD"] [unique_id "aovUZYkabZLAO30ap2-p3AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-21 03:02:03
(3 days ago)
[FriAug2105:02:00.0770342026][security2:error][pid510851:tid510896][client172.68.175.72:0]ModSecurit ...
show more
[FriAug2105:02:00.0770342026][security2:error][pid510851:tid510896][client172.68.175.72:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"danielasilvia.ch\"][uri\"/.git/HEAD\"][unique_id\"aoe_qI8BKBKByXHEybcPlwAAAck\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 20:29:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 16:29:08.104062 2026] [security2:error] [pid 19865:tid 19865] [client 172.68.175.72:10443] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gh057.io"] [uri "/.git/config"] [unique_id "aodjlOPQ6sYabNK_JMtVawAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:37:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:37:17.936105 2026] [security2:error] [pid 3113:tid 3113] [client 172.68.175.72:10054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.koshland.us"] [uri "/.git/HEAD"] [unique_id "aoZMPYeJ9JloFKyG0uySMQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 23:11:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 19:11:10.911721 2026] [security2:error] [pid 23163:tid 23163] [client 172.68.175.72:12381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.arcdesign.me"] [uri "/.git/HEAD"] [unique_id "aoY4DrYiDJ8fFWzFjTQy1gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-08-19 11:05:56
(4 days ago)
dot file probe
Web App Attack
๐ฉ๐ช
acadeova
2026-07-21 10:52:28
(1 month ago)
๐จ Recon detected (nft drop)
SRC=172.68.175.72
Observed=TCP dpt=2083 in=enp0s6 ttl=53
Time=recent(jou ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.175.72
Observed=TCP dpt=2083 in=enp0s6 ttl=53
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-02 04:13:27
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 00:13:22.510787 2026] [security2:error] [pid 19511:tid 19511] [client 172.68.175.72:12670] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.auguststoten.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.auguststoten.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ac3s4tdi-ZwmZEDORDT6RwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 06:48:19
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 02:48:11.451149 2026] [security2:error] [pid 465:tid 465] [client 172.68.175.72:10095] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.panesarlaw.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.panesarlaw.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "actuK9CBIB5EbOF2isalQgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-02 22:52:23
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.68.175.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 17:52:19.550985 2026] [security2:error] [pid 7627:tid 7627] [client 172.68.175.72:13990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.capitalswisscorp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.capitalswisscorp.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aaYUo38a-3aYn_CxkM7bsgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2025-12-10 05:53:49
(8 months ago)
172.68.175.72 - - [10/Dec/2025:1
...
Brute-Force
๐ฏ๐ต
S.O.B.A. Dev.
2025-11-26 21:04:15
(8 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
mawan
2025-07-03 07:14:38
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-15 08:46:48
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack