πΊπΈ
TPI-Abuse
2026-07-16 07:07:25
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 03:07:21.666741 2026] [security2:error] [pid 15352:tid 15352] [client 172.68.192.216:11320] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "lenukuhivabookings.com"] [uri "/.git/config"] [unique_id "aliDKXfuow7St8kAZAiMMAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
TheCoon
2026-06-29 03:45:01
(3 weeks ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
π·πΊ
DZBOT
2026-06-17 04:30:53
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-11 18:59:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 14:59:28.622947 2026] [security2:error] [pid 30097:tid 30097] [client 172.68.192.216:11742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desktop.joebankx.com"] [uri "/.git/config"] [unique_id "aisFkBnpT2Vgw0pX-T82swAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-06 17:32:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 13:32:13.325655 2026] [security2:error] [pid 17052:tid 17052] [client 172.68.192.216:11247] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "copiersgreensboro.computersraleigh.com"] [uri "/.git/config"] [unique_id "aiRZnZ5sQUfHmIPlhjVq2gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 15:04:28
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 11:04:21.175897 2026] [security2:error] [pid 22908:tid 22918] [client 172.68.192.216:13557] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.greaternorthmiamihistory.org"] [uri "/.git/config"] [unique_id "aiGT9TjGfrMuPIMOZFdqTAAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·πΊ
DZBOT
2026-05-22 16:13:18
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
WellSpring
2026-05-22 10:10:50
(1 month ago)
wordpress scan on 631.today/wp-admin/install.php β WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-11 02:26:24
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 22:26:15.324137 2026] [security2:error] [pid 25009:tid 25009] [client 172.68.192.216:12660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.loveoflearning.com"] [uri "/sftp-config.json"] [unique_id "agE-R1XhEQsCzdmz66dEFQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-30 13:06:19
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 09:06:10.440318 2026] [security2:error] [pid 15956:tid 15956] [client 172.68.192.216:13855] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jonrcortright.com"] [uri "/.git/config"] [unique_id "afNTwky-FtcmHyzEl9wFqQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-28 17:10:28
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 13:10:24.302478 2026] [security2:error] [pid 11420:tid 11420] [client 172.68.192.216:11920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sharperform.com"] [uri "/.git/config"] [unique_id "afDqAHKZVjDuFUFBF_AwXQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-26 16:17:03
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.192.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 12:16:55.207996 2026] [security2:error] [pid 21856:tid 21856] [client 172.68.192.216:13542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sanesoftware.com"] [uri "/.git/config"] [unique_id "ae46d5joCI-wUKERth9QyAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-18 00:37:16
(3 months ago)
[Sat Apr 18 02:37:15.804877 2026] [authz_core:error] [pid 6518] [client 172.68.192.216:12356] AH0163 ...
show more
[Sat Apr 18 02:37:15.804877 2026] [authz_core:error] [pid 6518] [client 172.68.192.216:12356] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Apr 18 02:37:15.863774 2026] [authz_core:error] [pid 6518] [client 172.68.192.216:12356] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat Apr 18 02:37:15.892825 2026] [authz_core:error] [pid 6518] [client 172.68.192.216:12356] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π«π·
masterguru
2026-04-02 13:09:48
(3 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-201)
Hacking
π«π·
masterguru
2026-03-30 13:46:15
(3 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-197)
Hacking