Anonymous
2026-08-30 22:12:32
(10 hours ago)
Attack detected: 172.69.222.102 [2026-08-30]
Categories: 21
--- wp2shell/batch exploit (1 hits) ---
...
show more
Attack detected: 172.69.222.102 [2026-08-30]
Categories: 21
--- wp2shell/batch exploit (1 hits) ---
172.69.222.102 - - [15/Aug/2026:21:22:12 +0000] "GET /?rest_route=/batch/v1 HTTP/2.0" 404 950 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 22:00:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 18:00:04.409415 2026] [security2:error] [pid 16672:tid 16672] [client 172.69.222.102:9865] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beta.flavornet.org"] [uri "/.git/config"] [unique_id "apNWZKKIfWZNuuuPmA52XQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
Mga Admin
2026-08-29 10:58:47
(1 day ago)
172.69.222.102 - - [29/Aug/2026:17:58:47 +0700] "GET /.git/HEAD HTTP/1.1" 404 69 "-" "Mozilla/5.0 (W ...
show more
172.69.222.102 - - [29/Aug/2026:17:58:47 +0700] "GET /.git/HEAD HTTP/1.1" 404 69 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 06:20:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:20:16.159583 2026] [security2:error] [pid 7124:tid 7124] [client 172.69.222.102:12512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.steinmetzjewelers.com"] [uri "/.git/config"] [unique_id "apJ6IIvPtrPqJZYcLnHuSgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:33:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:33:32.594257 2026] [security2:error] [pid 30070:tid 30070] [client 172.69.222.102:10171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deborbonfoundation.org"] [uri "/.git/HEAD"] [unique_id "apGqTC0DVZDWvJqTT7eqIAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 11:38:43
(3 days ago)
GET /.git/HEAD HTTP/1.1
...
Web App Attack
๐ฉ๐ช
4server
2026-08-27 05:33:51
(4 days ago)
[ThuAug2707:33:47.5010192026][security2:error][pid734189:tid734242][client172.69.222.102:0]ModSecuri ...
show more
[ThuAug2707:33:47.5010192026][security2:error][pid734189:tid734242][client172.69.222.102:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.elyon2.ch\"][uri\"/.git/config\"][unique_id\"ao_MO6YjRb78-lod0ELzMAAAAFE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 21:54:01
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 17:53:56.595816 2026] [security2:error] [pid 1690:tid 1690] [client 172.69.222.102:14206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "businessvaluationapp.com"] [uri "/.git/config"] [unique_id "ao9gdL4rZSvbkpEG-Jw-WgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 02:28:23
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:28:19.082880 2026] [security2:error] [pid 3164280:tid 3164379] [client 172.69.222.102:13782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.metabotic.com"] [uri "/.git/HEAD"] [unique_id "ao5PQ7P5Pd-_fpWxKZy77wAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-25 22:01:43
(5 days ago)
Auto-ban: >3000 req/min op 2026-08-25
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-24 11:34:02
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:33:55.217359 2026] [security2:error] [pid 30886:tid 30886] [client 172.69.222.102:14014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kathleenullmann.com"] [uri "/.git/config"] [unique_id "aowsI9SXXPWWvVGkJacCJQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-24 03:06:57
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 02:59:36
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 22:59:28.249203 2026] [security2:error] [pid 9695:tid 9695] [client 172.69.222.102:10490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.patrickjolly.us"] [uri "/.git/config"] [unique_id "aouzkA9gOPdMwRrkaKw19QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:54:19
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:54:11.995031 2026] [security2:error] [pid 3483158:tid 3483183] [client 172.69.222.102:10688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.certifiedprojectmanager.us"] [uri "/.git/HEAD"] [unique_id "aoFek650vfv0wraRUwaHtwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-15 22:07:00
(2 weeks ago)
Attack detected: 172.69.222.102 [2026-08-15]
Categories: 21
--- wp2shell/batch exploit (1 hits) ---
...
show more
Attack detected: 172.69.222.102 [2026-08-15]
Categories: 21
--- wp2shell/batch exploit (1 hits) ---
172.69.222.102 - - [15/Aug/2026:21:22:12 +0000] "GET /?rest_route=/batch/v1 HTTP/2.0" 404 950 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Web App Attack