๐ซ๐ฎ
kumiko
2026-09-01 13:34:37
(16 hours ago)
[2026-09-01 16:34:36] Probing for dotfiles
"GET /.git/config HTTP/2.0" 403
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-31 18:34:56
(1 day ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:17:52
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:17:46.712798 2026] [security2:error] [pid 25846:tid 25852] [client 172.71.118.180:11120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.giftsandgarland.com"] [uri "/.git/config"] [unique_id "apIzOrZMKQC7UXpuqgszZwAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-28 14:27:15
(4 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.71.118.180 (FR/France/-): 2 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.71.118.180 (FR/France/-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:13:46
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:13:43.439898 2026] [security2:error] [pid 21791:tid 21791] [client 172.71.118.180:14051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.willieplaymoreband.com"] [uri "/.git/config"] [unique_id "apGXl1Q-Wgk4yVc_0IVmlwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-28 04:21:54
(5 days ago)
[28/Aug/2026:07:21:53 +0300] -- 172.71.118.180 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[28/Aug/2026:07:21:53 +0300] -- 172.71.118.180 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 11:04:58
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 14:20:33
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 10:20:29.703914 2026] [security2:error] [pid 51452:tid 51489] [client 172.71.118.180:9766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.api.neotienda.com"] [uri "/.git/HEAD"] [unique_id "ao72LRJHY9jCM-meRWILogAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 13:36:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 09:36:41.092470 2026] [security2:error] [pid 28664:tid 28664] [client 172.71.118.180:11029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.businessimagination.com"] [uri "/.git/config"] [unique_id "ao2aaeUEAGYq1PSLrw-A9AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 10:15:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:15:02.438064 2026] [security2:error] [pid 26239:tid 26239] [client 172.71.118.180:10137] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.leadek.com"] [uri "/.git/config"] [unique_id "ao1rJsu_qHEvbwIZpPAX0wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 07:17:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:17:12.267973 2026] [security2:error] [pid 22898:tid 22898] [client 172.71.118.180:9534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.abundancecompany.com"] [uri "/.git/config"] [unique_id "ao1BeLrjOIayybJ1BEuGmAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-25 07:09:06
(1 week ago)
[Tue Aug 25 17:09:05.770371 2026] [security2:error] [pid 214409] [client 172.71.118.180:12737] [clie ...
show more
[Tue Aug 25 17:09:05.770371 2026] [security2:error] [pid 214409] [client 172.71.118.180:12737] [client 172.71.118.180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "balcomberetreat.com.au"] [uri "/.git/config"] [unique_id "ao0_kYg_EU50KkhJ0rqwSQAAAAA"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 02:38:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 22:38:41.038115 2026] [security2:error] [pid 28215:tid 28215] [client 172.71.118.180:11854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.biketurtlehill.com"] [uri "/.git/config"] [unique_id "ao0AMeVlNE-G8_-fXstaIQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 02:09:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 22:09:09.082314 2026] [security2:error] [pid 21725:tid 21725] [client 172.71.118.180:13758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stamford.org"] [uri "/.git/config"] [unique_id "aoz5Rbstr4CzIIBcXN5GRwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-24 22:29:30
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack