๐บ๐ธ
TPI-Abuse
2026-08-21 16:27:41
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 12:27:33.645594 2026] [security2:error] [pid 20346:tid 20346] [client 172.69.222.112:13421] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danielbrower.circleofsound.org"] [uri "/.git/HEAD"] [unique_id "aoh8de6vBoQ5NUgr3vXUsAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 23:00:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 19:00:06.123216 2026] [security2:error] [pid 2219:tid 2219] [client 172.69.222.112:12382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.talkingmess.com"] [uri "/.git/config"] [unique_id "aoeG9kLnc3xPB3toXE866AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 23:55:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 19:55:50.649016 2026] [security2:error] [pid 22034:tid 22034] [client 172.69.222.112:9780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ptfea.aquascapes.net"] [uri "/.git/config"] [unique_id "aoZChtxoS_X8ljnFia7NfQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 02:35:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 22:35:28.107249 2026] [security2:error] [pid 31138:tid 31138] [client 172.69.222.112:9623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rondeal.com"] [uri "/.git/config"] [unique_id "aoUWcIJx7QKBRd82ZDdF2gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 23:00:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 18:59:58.823708 2026] [security2:error] [pid 23546:tid 23546] [client 172.69.222.112:10503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.monkeyonabike.com"] [uri "/.git/HEAD"] [unique_id "aoTj7qA9hYoxhGcaCYtnuwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 09:57:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 05:57:01.819333 2026] [security2:error] [pid 12129:tid 12129] [client 172.69.222.112:13026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.reimaginingchess.com"] [uri "/.git/config"] [unique_id "aoQsbX5_nwP7gP1lblGlAQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 09:40:47
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 05:40:38.263648 2026] [security2:error] [pid 10222:tid 10222] [client 172.69.222.112:11516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.frickandfracks.com"] [uri "/.git/config"] [unique_id "aoQolvkpcsP8pA-7wu53LgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 09:17:00
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 05:16:53.585595 2026] [security2:error] [pid 3513:tid 3527] [client 172.69.222.112:13717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ilovemyparrot.com"] [uri "/.git/HEAD"] [unique_id "aoQjBYIBCMYMGepATyvKVAAAAcs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 03:56:01
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 23:55:54.892252 2026] [security2:error] [pid 12531:tid 12531] [client 172.69.222.112:11539] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pleasefixmycomputer.com"] [uri "/.git/HEAD"] [unique_id "aoPXymq62e_snSIY0WL-CAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-15 08:05:08
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ง๐ช
madeit
2026-08-09 04:59:54
(1 week ago)
Web App Attack
๐ฌ๐ง
OptimusGO
2026-08-07 19:37:44
(2 weeks ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-07 20:37:44 UTC
Log evidence:
172.69.222.112 - - [07/Aug/2026:20:37:42 +0100] "GET /api/index%2ejs HTTP/1.1" 404 118 "-" "curl/8.7.1"
08/07/2026-20:37:42.133215 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.69.222.112:11283 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
Anonymous
2026-07-29 18:53:25
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 weeks ago)
Automated Apache web application probing in selected 24h window; attempts=60, unique_paths=56, error ...
show more
Automated Apache web application probing in selected 24h window; attempts=60, unique_paths=56, error_responses=10; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 weeks ago)
Apache probe; attempts=60; exact paths: /2023/.env | /.env.development | /.env.kubernetes | /.env.pr ...
show more
Apache probe; attempts=60; exact paths: /2023/.env | /.env.development | /.env.kubernetes | /.env.production.local | /.env.test | /.env.tmp | /actuator/health | /actuator/threaddump | /api/.env.local | /api/core/.env | /app/.env.development | /app/.env.production | /clients/.env | /core/.env | /core/app/.env | /credentials/.env | /credentials/.env.production | /docker/.env | /home/ec2-user/.aws/logs/.env | /home/ec2-user/.local/bin/aws/.env | /home/ec2-user/.ssh/aws/.env | /home/ec2-user/bin/aws/bin/.env | /home/ec2-user/bin/aws/scripts/.env | /home/ec2-user/env/bin/aws/tools/.env | /home/ec2-user/envs/.env | /home/ec2-user/miniconda/bin/aws/lib/.env | /home/ec2-user/miniconda/envs/.env | /laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php | /main/.env | /production/.env | /public/.env | /settings/.env | /sites/.env | /testing/.env | /twilio/.cache/.env | /twilio/.cache/bin/aws/scripts/.env | /twili | ... [56 exact paths total]
show less
Web App Attack