๐บ๐ธ
TPI-Abuse
2026-08-21 20:45:31
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 16:45:22.673083 2026] [security2:error] [pid 30294:tid 30294] [client 172.69.222.42:10571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.afdfurniture.com"] [uri "/.git/config"] [unique_id "aoi44i9a-TlFYzfV2x9_jwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 18:17:44
(9 hours ago)
(mod_security) mod_security (id:949110) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 14:17:40.998048 2026] [security2:error] [pid 1103:tid 1103] [client 172.69.222.42:11588] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "delcano.org"] [uri "/.git/config"] [unique_id "aoiWRNzwvm1f3AZhQUT9mgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 16:48:22
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 12:48:14.575670 2026] [security2:error] [pid 10982:tid 10982] [client 172.69.222.42:10752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aupapierjaponais.com"] [uri "/.git/HEAD"] [unique_id "aoiBThdstS2XGDJAY-PnSAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 14:00:04
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 09:59:57.911962 2026] [security2:error] [pid 22471:tid 22508] [client 172.69.222.42:14093] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "2291106.com"] [uri "/.git/config"] [unique_id "aohZ3e7vg3qvqccGBWRC1QAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 10:30:59
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 06:30:51.810946 2026] [security2:error] [pid 5810:tid 5810] [client 172.69.222.42:9468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.edscontracting.com"] [uri "/.git/HEAD"] [unique_id "aogo28BWSjvFi9CEJPTLDQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Little Iguana
2026-08-21 09:57:53
(17 hours ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-21 06:56:04
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 02:55:57.888868 2026] [security2:error] [pid 28295:tid 28295] [client 172.69.222.42:9646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.craftammie.com"] [uri "/.git/config"] [unique_id "aof2fbeE13zDly_F5SOUlAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 00:16:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 20:15:59.614141 2026] [security2:error] [pid 14463:tid 14463] [client 172.69.222.42:12169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lemobba.com"] [uri "/.git/config"] [unique_id "aoeYv7GOL-Z1djChcKuq9wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-20 22:00:26
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-20
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-20 10:22:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 06:22:44.737222 2026] [security2:error] [pid 31491:tid 31491] [client 172.69.222.42:12635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.customhumanrobots.internetnameregistration.com"] [uri "/.git/HEAD"] [unique_id "aobVdEkHuQcXm5j-5dpDygAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-08-20 00:27:51
(2 days ago)
20/Aug/2026:02:27:50.737586 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
20/Aug/2026:02:27:50.737586 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.69.222.42] ModSecurity: Warning. Pattern match "^(?i:file|ftps?|https?):\\\\\\\\/\\\\\\\\/(?:\\\\\\\\d{1,3}\\\\\\\\.\\\\\\\\d{1,3}\\\\\\\\.\\\\\\\\d{1,3}\\\\\\\\.\\\\\\\\d{1,3})" at ARGS:file. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-931-APPLICATION-ATTACK-RFI.conf"] [line "56"] [id "931100"] [msg "Possible Remote File Inclusion (RFI) Attack: URL Parameter using IP Address"] [data "Matched Data: http://169.254.169.254 found within ARGS:file: http://169.254.169.254/latest/meta-data/iam/info"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-rfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/175/253"] [hostname "www.el-hacker.org"] [uri "/fetch"] [unique_id "aoZKBiamq6u7IaUhoEMQQwADuDY"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 00:03:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 20:03:46.186882 2026] [security2:error] [pid 6174:tid 6174] [client 172.69.222.42:12422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.melton.space"] [uri "/.git/HEAD"] [unique_id "aoZEYiCBQiBj3liarwoc_wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 22:26:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 18:26:16.408793 2026] [security2:error] [pid 24248:tid 24248] [client 172.69.222.42:12928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.socialenterprise.net"] [uri "/.git/config"] [unique_id "aoYtiG6BksC_SogNFwh9twAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 02:36:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 22:36:16.767014 2026] [security2:error] [pid 21306:tid 21306] [client 172.69.222.42:12023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.register-yacht-bvi.com"] [uri "/.git/HEAD"] [unique_id "aoUWoHiIr6GLh7iHsRKPAQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 01:50:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 21:50:16.721986 2026] [security2:error] [pid 16145:tid 16145] [client 172.69.222.42:14066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jimhermelband.com"] [uri "/.git/HEAD"] [unique_id "aoUL2Kx2GMgoUclTjVyDIAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack