๐บ๐ธ
TPI-Abuse
2026-08-29 03:26:09
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:26:03.505707 2026] [security2:error] [pid 9821:tid 9979] [client 172.69.223.200:13073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.salvoni.com"] [uri "/.git/HEAD"] [unique_id "apJRS9lOtgmj56t30B6RiQAAAlg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:56:48
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:56:39.762545 2026] [security2:error] [pid 21237:tid 21237] [client 172.69.223.200:11318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.isaacsonpaintings.com"] [uri "/.git/config"] [unique_id "apIgN8mxFsL7TYm39MMhHwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 08:14:10
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 04:14:02.549723 2026] [security2:error] [pid 5337:tid 5337] [client 172.69.223.200:10155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.xtremeautodetailing.com"] [uri "/.git/HEAD"] [unique_id "apFDShawXD2wrtZev7MV1wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-27 03:38:19
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 13:01:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:01:05.821211 2026] [security2:error] [pid 30295:tid 30295] [client 172.69.223.200:14214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lusocleaningservice.com"] [uri "/.git/config"] [unique_id "ao7jkeQGyIMK3u7rR_A7oAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-26 01:44:10
(3 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-08-25 18:13:12
(3 days ago)
172.69.223.200 - - [25/Aug/2026:20:13:09 +0200] "GET /%2eterraform.tfstate HTTP/1.1" 403 124 "-" "cu ...
show more
172.69.223.200 - - [25/Aug/2026:20:13:09 +0200] "GET /%2eterraform.tfstate HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.223.200 - - [25/Aug/2026:20:13:10 +0200] "GET /%2eterraform/credentials.tfrc.json HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.223.200 - - [25/Aug/2026:20:13:10 +0200] "GET /%2eaws/sso/cache HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.223.200 - - [25/Aug/2026:20:13:10 +0200] "GET /client.key HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.223.200 - - [25/Aug/2026:20:13:10 +0200] "GET /client.pem HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.223.200 - - [25/Aug/2026:20:13:10 +0200] "GET /ssl/certs HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.223.200 - - [25/Aug/2026:20:13:10 +0200] "GET /ssl/private HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.223.200 - - [25/Aug/2026:20:13:10 +0200] "GET /letsencrypt/live HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.223.200 - - [25/Aug/2026:20:13:10 +0200] "GET /oauth-public.key HTTP/1.1" 403 124 "-" "curl/8.7.1"
172.69.223.200 - - [25/Aug/2026:20:13:10 +0200]
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 12:34:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:33:57.703411 2026] [security2:error] [pid 1362:tid 1362] [client 172.69.223.200:9889] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.arklatexds.com"] [uri "/.git/config"] [unique_id "ao2LtQjCRNk_lTIlDVDfgAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-25 03:03:33
(4 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.69.223.200 (FR/France/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.69.223.200 (FR/France/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 14:26:44
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 10:26:38.423787 2026] [security2:error] [pid 26333:tid 26333] [client 172.69.223.200:11744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.marklex.com"] [uri "/.git/HEAD"] [unique_id "aoxUnhIIGx64lRfMoytCnAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 11:32:40
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:32:31.842906 2026] [security2:error] [pid 28569:tid 28569] [client 172.69.223.200:13448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mavikalem.org"] [uri "/.git/config"] [unique_id "aowrzwuARVm16b8Y8ZY5cgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 08:49:02
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 04:48:56.151706 2026] [security2:error] [pid 7257:tid 7257] [client 172.69.223.200:11349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tonynvn.me"] [uri "/.git/config"] [unique_id "aowFeEHCdtfbdtNi8i3RcQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-10 13:26:21
(2 weeks ago)
Web App Attack
๐บ๐ธ
mawan
2026-07-22 01:39:03
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 10:22:00
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 06:21:51.743623 2026] [security2:error] [pid 20755:tid 20755] [client 172.69.223.200:9660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gevieworld.com"] [uri "/.git/config"] [unique_id "aldfP75OYJD5boFjP-_vKAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack