๐บ๐ธ
TPI-Abuse
2026-08-27 04:31:57
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:31:50.984372 2026] [security2:error] [pid 16705:tid 16705] [client 172.69.223.152:11787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.artfranz.com"] [uri "/.git/HEAD"] [unique_id "ao-9tmIocM-UMg98DZwQVwAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 03:06:59
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:06:50.700288 2026] [security2:error] [pid 4962:tid 4962] [client 172.69.223.152:10629] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.trevthomas.com"] [uri "/.git/config"] [unique_id "ao-pyqH2syFdOh1V-gLy1QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 21:21:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 17:21:17.896589 2026] [security2:error] [pid 26800:tid 26824] [client 172.69.223.152:11742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aapm.info"] [uri "/.git/HEAD"] [unique_id "ao4HTZ2Jy1j09U87M3sZMgAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 17:19:32
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 13:19:28.123653 2026] [security2:error] [pid 27166:tid 27166] [client 172.69.223.152:13272] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.creators.freedrm.org"] [uri "/.git/config"] [unique_id "ao3OoBMq87kKyM_QxNH6RgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 16:55:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 12:55:10.250075 2026] [security2:error] [pid 14729:tid 14729] [client 172.69.223.152:10941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.noshsf.com"] [uri "/.git/HEAD"] [unique_id "ao3I7oOhFV2g4fAmgLJFPQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 07:15:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:15:50.237468 2026] [security2:error] [pid 21685:tid 21685] [client 172.69.223.152:13771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.sabecocont.com"] [uri "/.git/HEAD"] [unique_id "ao1BJvTkKoXm_-49099zKgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 22:56:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 18:56:09.416267 2026] [security2:error] [pid 2987:tid 3002] [client 172.69.223.152:10035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rosendalsateri.com"] [uri "/.git/config"] [unique_id "aozMCa2GOyfrdxks29zedAAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-24 16:18:56
(2 days ago)
cloudlinux2 fail2ban: 2026-08-24 18:14:27,424 fail2ban.filter [1464]: INFO [plesk-apache] ...
show more
cloudlinux2 fail2ban: 2026-08-24 18:14:27,424 fail2ban.filter [1464]: INFO [plesk-apache] Found 68.155.159.216 - 2026-08-24 18:14:27cloudlinux2 fail2ban: 2026-08-24 18:14:56,207 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 172.69.223.152 - 2026-08-24 18:14:56cloudlinux2 fail2ban: 2026-08-24 18:14:56,179 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 172.69.223.152 - 2026-08-24 18:14:56cloudlinux2 fail2ban: 2026-08-24 18:15:25,199 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 68.155.159.216 - 2026-08-24 18:15:25cloudlinux2 fail2ban: 2026-08-24 18:15:57,443 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.79.195 - 2026-08-24 18:15:54cloudlinux2 fail2ban: 2026-08-24 18:15:53,544 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 195.63.29.126 - 2026-08-24 18:15:53cloudlinux2 fail2ban: 2026-08-24 18:16:00,467 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.83.71 - 2026-08-24 18:15:5
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 08:34:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 04:34:45.517384 2026] [security2:error] [pid 21798:tid 21798] [client 172.69.223.152:11217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gasoilliquidsdaily.com"] [uri "/.git/config"] [unique_id "aowCJdRl-OpykqKcFNOJ4wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:29:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:29:30.972580 2026] [security2:error] [pid 24144:tid 24165] [client 172.69.223.152:13203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.metaphysicalinstitute.com.aafm.us"] [uri "/.git/HEAD"] [unique_id "aoFm2m9WWiAOTA26f2V5aQAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
UnixPrime
2026-07-27 18:18:50
(4 weeks ago)
172.69.223.152 - - [27/Jul/2026:20:18:48 +0200] "GET /.env.preprod HTTP/1.1" 404 9 "-" "Mozilla/5.0 ...
show more
172.69.223.152 - - [27/Jul/2026:20:18:48 +0200] "GET /.env.preprod HTTP/1.1" 404 9 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.69.223.152 - - [27/Jul/2026:20:18:48 +0200] "GET /.env.uat HTTP/1.1" 404 9 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 09:27:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 05:27:11.691501 2026] [security2:error] [pid 11324:tid 11324] [client 172.69.223.152:10849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myouenji.org"] [uri "/.env.bak"] [unique_id "aldSb9O_YFzDaFLxPAPy7gAAAAA"], referer: https://www.google.com/search?q=myouenji.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
UnixPrime
2026-07-14 15:48:12
(1 month ago)
172.69.223.152 - - [14/Jul/2026:17:48:08 +0200] "GET /api/v2/sync/maindata?rid=900 HTTP/1.1" 403 9 " ...
show more
172.69.223.152 - - [14/Jul/2026:17:48:08 +0200] "GET /api/v2/sync/maindata?rid=900 HTTP/1.1" 403 9 "https://torrent.pierrecn.pro/" "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0"
172.69.223.152 - - [14/Jul/2026:17:48:10 +0200] "GET /api/v2/sync/maindata?rid=900 HTTP/1.1" 403 9 "https://torrent.pierrecn.pro/" "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0"
172.69.223.152 - - [14/Jul/2026:17:48:12 +0200] "GET /api/v2/sync/maindata?rid=900 HTTP/1.1" 403 9 "https://torrent.pierrecn.pro/" "Mozilla/5.0 (X11; Linux x86_64; rv:151.0) Gecko/20100101 Firefox/151.0"
...
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
mawan
2026-07-09 21:16:20
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฆ๐ฑ
router.al
2026-06-04 12:54:54
(2 months ago)
06/04/2026-12:54:54.298200 172.69.223.152 Protocol: 6 ET WEB_SERVER PHP tags in HTTP POST
Hacking