๐จ๐ญ
4server
2026-09-01 21:17:13
(1 day ago)
[TueSep0123:17:06.6656942026][security2:error][pid758472:tid758790][client172.71.118.172:0]ModSecuri ...
show more
[TueSep0123:17:06.6656942026][security2:error][pid758472:tid758790][client172.71.118.172:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"aidconsultancy.ch\"][uri\"/.git/HEAD\"][unique_id\"apdA0rKNH4SnMEykyC7N7AAAAIk\"]
show less
Hacking
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-01 07:14:44
(1 day ago)
[Tue Sep 01 17:14:44.049715 2026] [security2:error] [pid 224727] [client 172.71.118.172:10627] [clie ...
show more
[Tue Sep 01 17:14:44.049715 2026] [security2:error] [pid 224727] [client 172.71.118.172:10627] [client 172.71.118.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ccideas.com.au"] [uri "/.git/config"] [unique_id "apZ7ZFUI7ZL4u67fLX3QKgAAAA8"]
...
show less
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-31 19:12:16
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐ฎ๐น
[email protected]
2026-08-30 22:08:01
(3 days ago)
172.71.118.172 - - [30/Aug/2026:14:14:29 +0200] "GET /.git/HEAD HTTP/2.0" 404 460 "-" "Mozilla/5.0 ( ...
show more
172.71.118.172 - - [30/Aug/2026:14:14:29 +0200] "GET /.git/HEAD HTTP/2.0" 404 460 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-30 03:09:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 23:09:25.154008 2026] [security2:error] [pid 18430:tid 18430] [client 172.71.118.172:11845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sunshinenv.com"] [uri "/.git/HEAD"] [unique_id "apOe5S-ZkyPHrhoL2nSTQgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 13:32:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 09:32:23.826781 2026] [security2:error] [pid 2694:tid 2694] [client 172.71.118.172:13252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.therealseska.com"] [uri "/.git/HEAD"] [unique_id "apLfZ77uMP2Sj2BzoBwVdQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 06:36:34
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:36:26.548640 2026] [security2:error] [pid 13857:tid 13857] [client 172.71.118.172:10766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mdp-interiors.com"] [uri "/.git/HEAD"] [unique_id "apJ96rCrLHR2F34GBb6mxgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-28 14:11:53
(5 days ago)
[Sat Aug 29 00:11:52.273465 2026] [security2:error] [pid 648524] [client 172.71.118.172:12556] [clie ...
show more
[Sat Aug 29 00:11:52.273465 2026] [security2:error] [pid 648524] [client 172.71.118.172:12556] [client 172.71.118.172] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ccideas.com.au"] [uri "/.git/config"] [unique_id "apGXKCrJqgU6CsZR5wbmRQAAAAU"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:02:08
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:02:01.650467 2026] [security2:error] [pid 13056:tid 13056] [client 172.71.118.172:12978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.goodideagirl.com"] [uri "/.git/config"] [unique_id "apGGyQ32csQHvzadPqZsowAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 12:34:28
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:34:21.036830 2026] [security2:error] [pid 9742:tid 9742] [client 172.71.118.172:11537] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cthog.xyz"] [uri "/.git/config"] [unique_id "apGATYnBjmCABjIOQXoJBQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 06:08:51
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:08:43.208094 2026] [security2:error] [pid 18274:tid 18274] [client 172.71.118.172:11080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wl7ba.lbee.com"] [uri "/.git/HEAD"] [unique_id "ao_Ua_cWsfmQg9x11fKujQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 20:11:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 16:11:27.044484 2026] [security2:error] [pid 21443:tid 21443] [client 172.71.118.172:13001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.enjoy2dance.com"] [uri "/.git/config"] [unique_id "ao9Ib720uP83fx8fcN8epgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 19:03:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:03:03.398387 2026] [security2:error] [pid 51450:tid 51465] [client 172.71.118.172:10226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.isoceansl.com"] [uri "/.git/HEAD"] [unique_id "ao84Zw5IujEbOVUlEFqvvAAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-26 08:45:09
(1 week ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-08-26 05:06:06
(1 week ago)
Trying to access config files
Web App Attack