๐ช๐ธ
el-brujo
2026-08-24 05:42:30
(2 hours ago)
24/Aug/2026:07:42:30.318468 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
24/Aug/2026:07:42:30.318468 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.69.222.143] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "tails.elhacker.net"] [uri "/.git/HEAD"] [unique_id "aovZxmMSUd7UBBcsDjsdPwABa1Q"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 05:29:24
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 01:29:15.142110 2026] [security2:error] [pid 3076568:tid 3076592] [client 172.69.222.143:11800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.slingshotpro.com"] [uri "/.git/config"] [unique_id "aovWq6KQbElCZT8WjDLVkAAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-24 05:14:07
(2 hours ago)
2 attacks on VC URLs:
GET /.git/HEAD HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-23 14:49:03
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:48:56.546901 2026] [security2:error] [pid 28331:tid 28331] [client 172.69.222.143:13365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.poulsoncustomhomes.com"] [uri "/.git/config"] [unique_id "aosIWCzjq0Dezua4PoE73gAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 13:40:22
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:40:14.904904 2026] [security2:error] [pid 31000:tid 31000] [client 172.69.222.143:9961] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cemesur-vision21.com"] [uri "/.git/HEAD"] [unique_id "aor4Pgy1N-nHNF0fdNpJIAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 23:38:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 19:38:16.729884 2026] [security2:error] [pid 1480:tid 1480] [client 172.69.222.143:12801] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.anus.net"] [uri "/.git/config"] [unique_id "aojhaK_22RgU1INVK9VdsAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 21:32:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 17:32:24.489833 2026] [security2:error] [pid 3028:tid 3028] [client 172.69.222.143:9312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.buyperfumeonline.net"] [uri "/.git/HEAD"] [unique_id "aojD6L3huq2N_YakMLDPzgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-21 11:54:54
(2 days ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐จ๐ญ
4server
2026-08-21 05:48:28
(3 days ago)
[FriAug2107:48:21.8714062026][security2:error][pid301088:tid301247][client172.69.222.143:0]ModSecuri ...
show more
[FriAug2107:48:21.8714062026][security2:error][pid301088:tid301247][client172.69.222.143:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"465\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"stmconsulenze.ch\"][uri\"/.git/config\"][unique_id\"aofmpQMDQgisZiTXIc9PwwAAAAk\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 09:43:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 05:43:12.166481 2026] [security2:error] [pid 16122:tid 16122] [client 172.69.222.143:9471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.robertseyewear.com"] [uri "/.git/HEAD"] [unique_id "aobMMBgZlX3qdt8J6eKLzAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-19 18:55:33
(4 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 01:28:01
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 21:27:57.059662 2026] [security2:error] [pid 4987:tid 5181] [client 172.69.222.143:14178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ronibenzvi.com"] [uri "/.git/HEAD"] [unique_id "aoUGnRWfN12xOxfeEPN9TQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 13:17:31
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 09:17:23.216011 2026] [security2:error] [pid 18878:tid 18878] [client 172.69.222.143:10018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ceta-arts.com"] [uri "/.git/config"] [unique_id "aoRbY2yDQTvqFAn8tiv5EQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
Prcek
2026-08-17 08:46:23
(6 days ago)
PortScan:HOST=172.69.222.143,DPORTS=443
Port Scan
๐บ๐ธ
mawan
2026-08-08 10:43:36
(2 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack