๐ฉ๐ช
4server
2026-08-24 16:39:34
(29 minutes ago)
[MonAug2418:39:32.3143612026][security2:error][pid1288185:tid1288211][client172.69.222.91:0]ModSecur ...
show more
[MonAug2418:39:32.3143612026][security2:error][pid1288185:tid1288211][client172.69.222.91:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"aaaa6877.org\"][uri\"/.git/HEAD\"][unique_id\"aoxzxMiaiU8eU8lPFJvZNAAAAU8\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 13:38:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:38:53.376176 2026] [security2:error] [pid 22657:tid 22657] [client 172.69.222.91:11823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cnbruselas.com"] [uri "/.git/config"] [unique_id "aoxJbc7ox8csNTz5FF-BbwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 03:06:09
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 23:06:01.979326 2026] [security2:error] [pid 24519:tid 24519] [client 172.69.222.91:10492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "20dekopas.com"] [uri "/.git/HEAD"] [unique_id "aou1GVQqiVm3YoKulkaN8AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 17:13:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:13:48.728773 2026] [security2:error] [pid 11273:tid 11273] [client 172.69.222.91:11010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bipocmentalhealthcoalition.org"] [uri "/.git/HEAD"] [unique_id "aonYzEwxHasqtKJ2X1y-KAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 17:46:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 13:46:43.218621 2026] [security2:error] [pid 495:tid 495] [client 172.69.222.91:9539] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.technicallydental.com"] [uri "/.git/config"] [unique_id "aoiPA0qsG9bdhFtJ4J0ktQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 10:36:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 06:36:08.335085 2026] [security2:error] [pid 23809:tid 23809] [client 172.69.222.91:10752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theantidote.gregorii.com"] [uri "/.git/config"] [unique_id "aogqGHmT54oBWCBOLhhyMQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 23:05:37
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 19:05:30.438351 2026] [security2:error] [pid 10085:tid 10085] [client 172.69.222.91:11203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.surviquo.com"] [uri "/.git/HEAD"] [unique_id "aoTlOhEaZaqehS0K2mXL0QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 10:54:27
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 06:54:19.481502 2026] [security2:error] [pid 19003:tid 19003] [client 172.69.222.91:11729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fullyevil.com"] [uri "/.git/HEAD"] [unique_id "aoQ52yDnnGH9IZUXCUBQ9AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 10:00:20
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 06:00:15.355403 2026] [security2:error] [pid 30584:tid 30623] [client 172.69.222.91:13073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.paygulf.com"] [uri "/.git/config"] [unique_id "aoQtL3kt_2XqsKsd92CfzAAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
OptimusGO
2026-08-07 19:40:42
(2 weeks ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-07 20:40:41 UTC
Log evidence:
172.69.222.91 - - [07/Aug/2026:20:40:39 +0100] "GET /secrets/index%2ejs HTTP/1.1" 404 118 "-" "curl/8.7.1"
08/07/2026-20:40:39.455544 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.69.222.91:10902 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-15 02:06:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 22:06:25.063886 2026] [security2:error] [pid 23060:tid 23074] [client 172.69.222.91:9672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beltagin.com"] [uri "/.env.production"] [unique_id "albrIYzk7Q7h86jj230E4QAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐ฑ
router.al
2026-07-14 09:37:52
(1 month ago)
07/14/2026-09:37:51.950398 172.69.222.91 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple R ...
show more
07/14/2026-09:37:51.950398 172.69.222.91 Protocol: 6 ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML
show less
Hacking
๐บ๐ธ
mawan
2026-06-29 18:43:42
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฌ๐ง
OptimusGO
2026-06-27 23:34:47
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-28 00:34:47 UTC
Log evidence:
172.69.222.91 - - [28/Jun/2026:00:34:46 +0100] "GET /assets/js/aws-config.js HTTP/1.1" 404 118 "-" "curl/8.7.1"
06/28/2026-00:34:46.358612 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.69.222.91:12420 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
๐ง๐พ
lns.bz
2026-06-05 06:25:39
(2 months ago)
.env scanning [BY]
Web App Attack