๐ฉ๐ช
kkw
2026-09-18 14:40:19
(1 week ago)
[REDACTED] 172.69.223.140 - - [18/Sep/2026:16:40:14 +0200] "GET /server/backend/.env HTTP/2.0" 404 2 ...
show more
[REDACTED] 172.69.223.140 - - [18/Sep/2026:16:40:14 +0200] "GET /server/backend/.env HTTP/2.0" 404 282127 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 18:00:03
(1 week ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
Anonymous
2026-09-13 16:43:12
(1 week ago)
IP matched detection query many 3xx errors.
Brute-Force
๐ง๐ช
madeit
2026-09-08 09:41:55
(2 weeks ago)
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-09-01 11:12:26
(3 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-29 23:00:47
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 19:00:42.493523 2026] [security2:error] [pid 25300:tid 25300] [client 172.69.223.140:9768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.willmarksynthetics.com"] [uri "/.git/config"] [unique_id "apNkmiMApCD5HEWFsplVBQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 19:29:49
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 15:29:44.193761 2026] [security2:error] [pid 4051:tid 4051] [client 172.69.223.140:11161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manb.org"] [uri "/.git/HEAD"] [unique_id "apMzKCGiU5qx8e4YresUXwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 10:20:56
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:20:49.698380 2026] [security2:error] [pid 31550:tid 31550] [client 172.69.223.140:11648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.comsew.com.au"] [uri "/.git/config"] [unique_id "apAPgQ_0A6rZTsruCbsJGAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 08:28:51
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:28:45.364965 2026] [security2:error] [pid 23006:tid 23006] [client 172.69.223.140:11889] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proprocessor.com"] [uri "/.git/HEAD"] [unique_id "ao_1Pdm-uvlDRob5Qo21IgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 15:15:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 11:15:52.599665 2026] [security2:error] [pid 5015:tid 5015] [client 172.69.223.140:12690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wasabioldies.com"] [uri "/.git/config"] [unique_id "ao2xqC1UAQ7Q2twRK2RIiAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 01:45:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 21:45:50.909498 2026] [security2:error] [pid 31974:tid 31974] [client 172.69.223.140:11288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.frenosilent.ar"] [uri "/.git/HEAD"] [unique_id "aozzzhVij25V5Cixjv4VgQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 22:51:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 18:51:37.460124 2026] [security2:error] [pid 7130:tid 7130] [client 172.69.223.140:12706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dudleyanddudley.com"] [uri "/.git/HEAD"] [unique_id "aozK-Sau-rvbJnQ5VTwI7AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 03:43:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 23:43:20.078244 2026] [security2:error] [pid 9981:tid 9981] [client 172.69.223.140:11985] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.premierveterinarysurgery.com"] [uri "/.git/HEAD"] [unique_id "aou92L2fowggA2KDDLGmwgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 13:20:53
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:20:47.005340 2026] [security2:error] [pid 19595:tid 19595] [client 172.69.223.140:13961] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "qualiabookings.com"] [uri "/.git/HEAD"] [unique_id "aorzrzaVoNUhGrYxtOW0swAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 05:05:25
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:05:20.817357 2026] [security2:error] [pid 23648:tid 23648] [client 172.69.223.140:12752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sekelconsulting.com"] [uri "/.git/config"] [unique_id "aop_kEi5HIz3yxaV2IdUkgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack