๐บ๐ธ
TPI-Abuse
2026-08-22 17:46:24
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:46:17.623264 2026] [security2:error] [pid 4622:tid 4622] [client 172.69.222.87:10888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.neconebooks.com"] [uri "/.git/HEAD"] [unique_id "aongaWXb6s_3sBEnAzz8swAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 17:26:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:26:25.844269 2026] [security2:error] [pid 12141:tid 12141] [client 172.69.222.87:12643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haddadpharmacy.com"] [uri "/.git/config"] [unique_id "aonbwd09gsY6WjcaO8hJeAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 14:14:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 10:14:32.148300 2026] [security2:error] [pid 32148:tid 32148] [client 172.69.222.87:13359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chassell.info.dhsgrad.net"] [uri "/.git/HEAD"] [unique_id "aomuyOgyHykJNoM2DPmaUgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 05:21:07
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 01:21:01.498915 2026] [security2:error] [pid 4788:tid 4788] [client 172.69.222.87:12553] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ontrek.com"] [uri "/.git/config"] [unique_id "aokxvaUK5vQFrDvaTik44AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 00:22:42
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 20:22:34.281006 2026] [security2:error] [pid 9121:tid 9121] [client 172.69.222.87:9406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aokatheists.org"] [uri "/.git/config"] [unique_id "aojryieH8yAHddhnoiDvrgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 11:32:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 07:32:22.942164 2026] [security2:error] [pid 4398:tid 4398] [client 172.69.222.87:11540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.advantagept.org"] [uri "/.git/HEAD"] [unique_id "aog3RhyFwT5ldyEA_USTzQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 06:50:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 02:50:13.419564 2026] [security2:error] [pid 12455:tid 12455] [client 172.69.222.87:14223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intersession.intersession.net"] [uri "/.git/config"] [unique_id "aof1JQq1WsfxiLCRq9xwOgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-20 22:00:26
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-20
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-20 06:52:53
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 02:52:48.150864 2026] [security2:error] [pid 556:tid 556] [client 172.69.222.87:11464] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "omnustechnologies.com"] [uri "/.git/config"] [unique_id "aoakQJgMAak5PhpyCuWYxQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 02:11:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 22:11:08.831411 2026] [security2:error] [pid 5598:tid 5598] [client 172.69.222.87:11314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.sponsorzilla.com"] [uri "/.git/HEAD"] [unique_id "aoZiPI4IBbpig8smGNiYmgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 01:50:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 21:50:12.266497 2026] [security2:error] [pid 8393:tid 8393] [client 172.69.222.87:11801] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.burnbuns.com"] [uri "/.git/config"] [unique_id "aoUL1ALlBWJjZLBNwmecbwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 23:38:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 19:38:21.813789 2026] [security2:error] [pid 20860:tid 20860] [client 172.69.222.87:11632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.serviciodepinturadecasas.com"] [uri "/.git/HEAD"] [unique_id "aoTs7YWl9DR7eo4vRxsQCgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-11 13:58:08
(1 week ago)
Web App Attack
Anonymous
2026-08-10 21:32:24
(1 week ago)
172.69.222.87 - - [10/Aug/2026:23:32:21 +0200] "GET /email/smtp%2eyml HTTP/1.1" 403 124 "-" "curl/8. ...
show more
172.69.222.87 - - [10/Aug/2026:23:32:21 +0200] "GET /email/smtp%2eyml HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.222.87 - - [10/Aug/2026:23:32:21 +0200] "GET /private/info%2ephp HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.222.87 - - [10/Aug/2026:23:32:21 +0200] "GET /%2eenv%2e%7B%7BDN%7D%7D HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.222.87 - - [10/Aug/2026:23:32:21 +0200] "GET /db_backup%2econf HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.222.87 - - [10/Aug/2026:23:32:21 +0200] "GET /core/private/site%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.222.87 - - [10/Aug/2026:23:32:22 +0200] "GET /conf/config%2eenv HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.222.87 - - [10/Aug/2026:23:32:22 +0200] "GET /config/email/mailgun_key%2etxt HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.222.87 - - [10/Aug/2026:23:32:22 +0200] "GET /%2essh/id_dsa%2epub%2ebak HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.222.87 - - [10/Aug/2026:23:32:22 +0200] "GET /secrets/aws-credentials%2etxt HTTP/1.1" 403 124 "-" "curl/8.7.1"
17
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-06 09:44:22
(2 weeks ago)
172.69.222.87 - - [06/Aug/2026:11:44:19 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
172.69.222.87 - - [06/Aug/2026:11:44:19 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
172.69.222.87 - - [06/Aug/2026:11:44:19 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
172.69.222.87 - - [06/Aug/2026:11:44:20 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
172.69.222.87 - - [06/Aug/2026:11:44:20 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
172.69.222.87 - - [06/Aug/2026:11:44:21 +0200] "GET //2020/wp-includes/wlwmanifest.xml
...
show less
Brute-Force
Web App Attack