๐บ๐ธ
TPI-Abuse
2026-08-24 08:30:38
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 04:30:30.016603 2026] [security2:error] [pid 8733:tid 8733] [client 172.68.175.94:13823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.register-yacht-italy.com"] [uri "/.git/config"] [unique_id "aowBJnuBOd0n01fzWAmINgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-24 06:07:30
(3 hours ago)
[MonAug2408:07:26.3731172026][security2:error][pid648277:tid648384][client172.68.175.94:0]ModSecurit ...
show more
[MonAug2408:07:26.3731172026][security2:error][pid648277:tid648384][client172.68.175.94:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"fondazionepetronillapontirone.ch\"][uri\"/.git/HEAD\"][unique_id\"aovfngIADuDC0e8GHE6JdwAAANQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 06:01:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 02:01:05.523461 2026] [security2:error] [pid 29469:tid 29469] [client 172.68.175.94:9429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dentsville398.org"] [uri "/.git/HEAD"] [unique_id "aoveIbGshaJZFJAjc-HzkgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 05:18:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 01:18:00.523518 2026] [security2:error] [pid 19602:tid 19602] [client 172.68.175.94:11373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.meghanmack.com"] [uri "/.git/HEAD"] [unique_id "aovUCA58S4TOVZsiB4Cg4wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 03:08:23
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 23:08:14.794031 2026] [security2:error] [pid 31310:tid 31310] [client 172.68.175.94:13697] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kln.jp"] [uri "/.git/HEAD"] [unique_id "aou1npGl2iSRQ1orKJuASgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 23:54:11
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 19:54:05.175745 2026] [security2:error] [pid 22669:tid 22669] [client 172.68.175.94:11304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pacepk.com"] [uri "/.git/HEAD"] [unique_id "aouIHYgwgAsgjVy8faBDAwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Little Iguana
2026-08-23 02:15:23
(1 day ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ฉ๐ช
FeG Deutschland
2026-08-23 00:08:37
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฎ๐น
[email protected]
2026-08-22 22:06:54
(1 day ago)
172.68.175.94 - - [22/Aug/2026:04:31:16 +0200] "GET /.git/HEAD HTTP/2.0" 404 460 "-" "Mozilla/5.0 (X ...
show more
172.68.175.94 - - [22/Aug/2026:04:31:16 +0200] "GET /.git/HEAD HTTP/2.0" 404 460 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
Hacking
Anonymous
2026-08-22 18:42:23
(1 day ago)
Web scanner: GET /.git/HEAD
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-22 10:09:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:09:27.307309 2026] [security2:error] [pid 19558:tid 19558] [client 172.68.175.94:14030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ashtangayogamelbourne.com.au"] [uri "/.git/HEAD"] [unique_id "aol1VxULITeuREIwLoI91QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-22 01:03:57
(2 days ago)
cloudlinux2 fail2ban: 2026-08-22 02:59:32,764 fail2ban.filter [1480]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-22 02:59:32,764 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.23.160.137 - 2026-08-22 02:59:32cloudlinux2 fail2ban: 2026-08-22 02:59:34,486 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.23.160.110 - 2026-08-22 02:59:34cloudlinux2 fail2ban: 2026-08-22 02:59:32,747 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.23.160.210 - 2026-08-22 02:59:32cloudlinux2 fail2ban: 2026-08-22 02:59:34,448 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.23.160.168 - 2026-08-22 02:59:34cloudlinux2 fail2ban: 2026-08-22 03:00:24,159 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 170.64.235.198 - 2026-08-22 03:00:24cloudlinux2 fail2ban: 2026-08-22 03:00:37,964 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.68.175.94 - 2026-08-22 03:00:37cloudlinux2 fail2ban: 2026-08-22 03:00:37,852 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.68.175.94 - 2026-08-2
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-21 11:49:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 07:48:56.890513 2026] [security2:error] [pid 24191:tid 24279] [client 172.68.175.94:12947] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.furball.co.uk"] [uri "/.git/config"] [unique_id "aog7KC31nM943mdFRbeQkgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 08:34:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.175.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 04:34:13.449726 2026] [security2:error] [pid 31413:tid 31413] [client 172.68.175.94:10373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oxford-gliding-club.co.uk"] [uri "/.git/HEAD"] [unique_id "aogNhXCjYGnWqQiFju05HgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-20 14:44:13
(3 days ago)
Try to connect to Port_Scan_443_stealth
Port Scan