๐บ๐ธ
TPI-Abuse
2026-08-22 13:45:46
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:949110) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:45:42.479590 2026] [security2:error] [pid 10103:tid 10103] [client 172.68.245.5:13258] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "slapai.org"] [uri "/.env.old"] [unique_id "aomoBjiplDapELhdIpJkQgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 01:31:40
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:31:31.765234 2026] [security2:error] [pid 3306:tid 3306] [client 172.68.245.5:11369] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.konahawaiirealty.com"] [uri "/.git/config"] [unique_id "aoO183g1S8ziFTGZeFcLHwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 00:10:49
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 20:10:45.571798 2026] [security2:error] [pid 25734:tid 25734] [client 172.68.245.5:10215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.scienceandpoetrywithgrandpa.xyz"] [uri "/.git/config"] [unique_id "aoJRhTy-urm7OlPt7IxFwQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 04:36:33
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:36:26.561813 2026] [security2:error] [pid 7577:tid 7577] [client 172.68.245.5:14256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.englishmagic.us"] [uri "/.git/HEAD"] [unique_id "aoE-SsJV06RTMamzZZXePwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:34:40
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:34:37.109670 2026] [security2:error] [pid 2593:tid 2593] [client 172.68.245.5:12542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.drstiso.com"] [uri "/.git/config"] [unique_id "aoEvzRSNEJi1raWtjhqBWAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 03:00:09
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 22:59:58.956844 2026] [security2:error] [pid 2554364:tid 2554364] [client 172.68.245.5:10522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pakistanvision.com"] [uri "/.git/config"] [unique_id "an0zLjD0gaZD40982XJOZQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 04:12:16
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 00:12:11.055830 2026] [security2:error] [pid 2151974:tid 2151995] [client 172.68.245.5:13188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.promoralchoice.org"] [uri "/.git/config"] [unique_id "anvym4a8r2aHWGqRHGD6vwAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 07:44:00
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 03:43:56.824006 2026] [security2:error] [pid 3984:tid 3995] [client 172.68.245.5:13885] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "catch-22productions.ceol.us"] [uri "/.git/config"] [unique_id "anrSvKbj8Q_hVW9js9FwEgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-11 05:02:47
(4 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 02:51:40
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 22:51:34.288796 2026] [security2:error] [pid 918161:tid 918214] [client 172.68.245.5:11024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.iacsb.com"] [uri "/.git/HEAD"] [unique_id "anqONhI4d_poVVkmKX3LWgAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=25; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.example ...
show more
Apache probe; attempts=25; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.example | /.env.local | /.env.old | /.env.php.bak | /.env.production | /.env.swp | /.git-credentials | /.git/HEAD | /.git/config | /.hermes/.env | /.openclaw/.env | /actuator | /actuator/configprops | /actuator/mappings | /admin/.env | /api/.env | /backend/.env | /config/.env | /config/.env.php | /core/.env | /web/.env
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 17:26:42
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 13:26:34.928033 2026] [security2:error] [pid 6032:tid 6032] [client 172.68.245.5:12963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grantjennings.com"] [uri "/.env.dev"] [unique_id "ahSGSvxtI8pRUHcIoDtnUwAAABc"], referer: https://www.google.com/search?q=grantjennings.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 11:39:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:39:21.736917 2026] [security2:error] [pid 4397:tid 4542] [client 172.68.245.5:12206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reattaforsale.com"] [uri "/.env.local"] [unique_id "agcF6YNB1lcs-zD9y2ZwsQAAAoU"], referer: https://www.google.com/search?q=reattaforsale.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-14 22:06:24
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-13.
show less
Web App Attack
SSH
Hacking
๐ฏ๐ต
Valhalla
2026-05-09 11:52:52
(3 months ago)
/.git/config
Hacking
Web App Attack