πΊπΈ
mashamal
2026-09-15 09:51:30
(1 day ago)
unauthorized access request
...
Web App Attack
π©πͺ
baphomet
2026-09-13 09:25:07
(3 days ago)
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.e ...
show more
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.env/wp-login/xmlrpc/phpmyadmin/.git).
jail=nginx-canary proto=tcp port=80,443 failures>=2 class=web-app-probe
these paths are not real apps on this host; hit is hostile recon
when=2026-09-13T09:25:07Z sensor=fail2ban role=web-canary
src=172.69.222.48
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 18:13:33
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 14:13:26.876009 2026] [security2:error] [pid 3049:tid 3049] [client 172.69.222.48:13994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.elianabeam.com.amybeam.com"] [uri "/.git/HEAD"] [unique_id "apMhRnaWYR58sGG-y1twDwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 12:18:40
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:18:36.181750 2026] [security2:error] [pid 23176:tid 23176] [client 172.69.222.48:12309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "capitalacc.anthonyanimalclinic.net"] [uri "/.git/HEAD"] [unique_id "apLOHHl27qQgFP1hkq9r5wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 06:49:25
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:49:21.916554 2026] [security2:error] [pid 19592:tid 19592] [client 172.69.222.48:11576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foothillsjasper.jaspercity.com"] [uri "/.git/config"] [unique_id "apEvccoU-KZm951FIuDLvAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 13:14:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:14:49.578530 2026] [security2:error] [pid 19927:tid 19927] [client 172.69.222.48:10590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kimpitchellandassociatesinc.com"] [uri "/.git/config"] [unique_id "apA4SYudtsVB-meNVaGPqgAAAG8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 16:23:10
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:23:03.794384 2026] [security2:error] [pid 29590:tid 29590] [client 172.69.222.48:11440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.franchiseconsultants.org"] [uri "/.git/HEAD"] [unique_id "ao8S5-cy3kjaetEQHh1d9AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 02:10:28
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:10:22.166352 2026] [security2:error] [pid 25074:tid 25074] [client 172.69.222.48:9469] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eiltopofictioncritique.com"] [uri "/.git/config"] [unique_id "ao5LDqWbPZWmNkAmMSuquAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 20:59:01
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 16:58:54.922811 2026] [security2:error] [pid 22247:tid 22247] [client 172.69.222.48:10368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.alpha-hk.com"] [uri "/.git/HEAD"] [unique_id "ao4CDv6jWaf1KPlHMnt9KgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-25 16:13:02
(3 weeks ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 09:43:55
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:43:51.205347 2026] [security2:error] [pid 2320:tid 2320] [client 172.69.222.48:13312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rxrepconnect.circlehealthcaregroup.com"] [uri "/.git/HEAD"] [unique_id "ao1j12C11RxjWKKKi3AhCgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 04:39:22
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 00:39:17.009195 2026] [security2:error] [pid 10804:tid 10804] [client 172.69.222.48:10886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.faeriefeelers.com"] [uri "/.git/config"] [unique_id "ao0cdZ_3rSLXOmv5c6Q4pQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 16:38:09
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 12:38:05.641127 2026] [security2:error] [pid 22826:tid 22826] [client 172.69.222.48:10011] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.despojosocial.com"] [uri "/.git/config"] [unique_id "aoxzbfOiNtOSTfAekBZPHgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-05 16:52:07
(1 month ago)
Web App Attack
π§π·
mateus.vicente
2026-08-04 23:46:25
(1 month ago)
[2026-08-04T23:46:24Z] Requests to sensitive Apache endpoints and path traversal patterns. (srv-app)
Brute-Force
Bad Web Bot
Web App Attack