๐ซ๐ท
dynamix
2026-10-04 03:57:56
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-23 21:34:41
(1 week ago)
Web App Attack
๐ง๐ช
madeit
2026-09-01 12:50:49
(1 month ago)
Web App Attack
๐ง๐ช
madeit
2026-08-23 21:40:40
(1 month ago)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-22 22:03:23
(1 month ago)
Auto-ban: >3000 req/min op 2026-08-22
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-22 21:45:28
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 17:45:21.891992 2026] [security2:error] [pid 14479:tid 14479] [client 172.68.245.23:13929] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.pleasejustfixit.org.cescfoundation.org"] [uri "/.git/config"] [unique_id "aooYccfyndE4xzMN7DFWxwAAAAc"], referer: https://www.google.com/search?q=www.pleasejustfixit.org.cescfoundation.org
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 18:25:01
(1 month ago)
(caddyscan) Scanner path probe from 172.68.245.23 (US/United States/-): 5 in the last 3600 secs; Por ...
show more
(caddyscan) Scanner path probe from 172.68.245.23 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.68.245.23 - - [22/Aug/2026:18:24:51 +0000] "GET /wp-admin/maint/maint.php HTTP/1.1"
[REDACTED] 200 2627 172.68.245.23 - - [22/Aug/2026:18:24:53 +0000] "GET /wp-admin/js/wp-conflg.php?p= HTTP/1.1"
[REDACTED] 200 2627 172.68.245.23 - - [22/Aug/2026:18:24:54 +0000] "GET /wp-admin/wp-conflg.php?p= HTTP/1.1"
[REDACTED] 200 2627 172.68.245.23 - - [22/Aug/2026:18:24:54 +0000] "GET /wp-admin/css/wp-conflg.php?p= HTTP/1.1"
[REDACTED] 200 2627 172.68.245.23 - - [22/Aug/2026:18:24:56 +0000] "GET /wp-admin/maint/admin.php HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-18 01:30:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:30:45.193051 2026] [security2:error] [pid 32463:tid 32463] [client 172.68.245.23:13860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.holesandcorners.com"] [uri "/.git/config"] [unique_id "aoO1xTBNqXoq1Te9ckCX9QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 01:09:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:08:59.242876 2026] [security2:error] [pid 3080:tid 3080] [client 172.68.245.23:13485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.taekwondoit.com"] [uri "/.git/config"] [unique_id "aoOwqzFLd7VoHVodmpexJAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:26:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:26:03.963274 2026] [security2:error] [pid 29540:tid 29540] [client 172.68.245.23:12061] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.michaelhick.com"] [uri "/.git/HEAD"] [unique_id "aoK3i2XDRhgkJnpSVDgwNwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:56:18
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:56:13.455304 2026] [security2:error] [pid 15140:tid 15140] [client 172.68.245.23:9962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.major33.com"] [uri "/.git/HEAD"] [unique_id "aoKifSAcH5Z2QWbwGhkWLAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:09:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:09:51.613450 2026] [security2:error] [pid 9022:tid 9022] [client 172.68.245.23:10184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.rannals.com"] [uri "/.git/config"] [unique_id "aoJtb6h9Ld5QSvt9lgwMHgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 11:39:59
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 07:39:51.671430 2026] [security2:error] [pid 24512:tid 24512] [client 172.68.245.23:9906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "studioyau.com"] [uri "/.git/config"] [unique_id "aoGhh8KtDZ8mRq4N9MEuTQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 11:00:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 07:00:22.597482 2026] [security2:error] [pid 15420:tid 15420] [client 172.68.245.23:14315] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tomhatcher.us"] [uri "/.git/HEAD"] [unique_id "aoGYRmwn4ODElM1iLNLK3AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 05:17:21
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:17:15.515917 2026] [security2:error] [pid 2068009:tid 2068009] [client 172.68.245.23:11403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mark-et-ing-1llc.com.nldi.us"] [uri "/.git/HEAD"] [unique_id "aoFH2wnIED3TJwLU0nMfrAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack