Anonymous
2026-09-06 20:30:06
(3 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
abdubhai
2026-09-06 15:02:06
(3 days ago)
172.69.223.91 - - [06/Sep/2026:2
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-29 16:31:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 12:30:56.237483 2026] [security2:error] [pid 27035:tid 27035] [client 172.69.223.91:14293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.comsew.com.au"] [uri "/.git/HEAD"] [unique_id "apMJQKOI6TmqabxurC-H7AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-29 16:21:32
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:07:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:07:22.526226 2026] [security2:error] [pid 25192:tid 25192] [client 172.69.223.91:13789] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ecrecorp.com"] [uri "/.git/HEAD"] [unique_id "apIUqiJf2WHHBGCbbaeCowAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 02:04:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 22:04:48.220303 2026] [security2:error] [pid 11139:tid 11139] [client 172.69.223.91:9281] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.deborahbein.com"] [uri "/.git/config"] [unique_id "apDswE5divkaXxWila3ZFwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 07:16:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 03:16:15.411164 2026] [security2:error] [pid 27852:tid 27852] [client 172.69.223.91:10211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "firstampersand.kathiehazlett.com"] [uri "/.git/config"] [unique_id "ao_kPzmmO1dJH0HcrkwOYQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 21:53:51
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 17:53:42.615729 2026] [security2:error] [pid 21539:tid 21539] [client 172.69.223.91:11785] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.murpf.com"] [uri "/.git/HEAD"] [unique_id "ao9gZnxNRjSP0vvT5voWOwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 14:09:30
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 10:09:25.176363 2026] [security2:error] [pid 14547:tid 14547] [client 172.69.223.91:14259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tucek.org"] [uri "/.git/HEAD"] [unique_id "ao7zlaeM-aQnzEGtwvm3dQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 13:06:06
(2 weeks ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 09:54:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:54:49.916695 2026] [security2:error] [pid 16447:tid 16447] [client 172.69.223.91:12445] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.academicaic.com"] [uri "/.git/config"] [unique_id "ao636QIHM2E7saWFVwIecgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 05:34:04
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:33:58.227295 2026] [security2:error] [pid 14674:tid 14674] [client 172.69.223.91:13843] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starsmogsandiego.smogsandiego.com"] [uri "/.git/config"] [unique_id "ao56xpNjpP1LN4S_yPSTYAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-26 02:31:21
(2 weeks ago)
[WedAug2604:31:13.4318782026][security2:error][pid2625747:tid2625763][client172.69.223.91:0]ModSecur ...
show more
[WedAug2604:31:13.4318782026][security2:error][pid2625747:tid2625763][client172.69.223.91:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.sesael.ch\"][uri\"/.git/HEAD\"][unique_id\"ao5P8Tm7S3T7jThbTQokFgAAAQs\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 00:09:50
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.223.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 20:09:45.714802 2026] [security2:error] [pid 17756:tid 17756] [client 172.69.223.91:9371] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eclipsesoftware.andrew.weigel.name"] [uri "/.git/HEAD"] [unique_id "ao4uybYOvKjTxa_BgjkGcQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-24 22:02:29
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-08-24
Web App Attack
SSH
Hacking