π³π΄
jad-abuse
2026-09-02 06:44:18
(8 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 23:40:26
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 19:40:20.247450 2026] [security2:error] [pid 20793:tid 20880] [client 172.71.118.186:10431] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nextlevelpsych.com"] [uri "/.git/config"] [unique_id "apdiZI-haaGjsbhqY3V0EgAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 06:00:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:00:37.330075 2026] [security2:error] [pid 4537:tid 4537] [client 172.71.118.186:10535] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "realdesigninterior.com"] [uri "/.git/HEAD"] [unique_id "apZqBakBsnyN9JeQnHQv-AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 08:30:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 04:30:24.929702 2026] [security2:error] [pid 11170:tid 11170] [client 172.71.118.186:10517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "palmerattaway.com"] [uri "/.git/config"] [unique_id "apPqII9p9Y9tmt6TWvjj_wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 05:38:39
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:38:30.273710 2026] [security2:error] [pid 28570:tid 28570] [client 172.71.118.186:12180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "masterpiecemorgans.com"] [uri "/.git/config"] [unique_id "apJwVtxWL_hOfljM_LkmEQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 15:56:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:55:58.914344 2026] [security2:error] [pid 10927:tid 10985] [client 172.71.118.186:10524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.icecc.com"] [uri "/.git/config"] [unique_id "apGvjoUXMKUZ2_QkMQ5DmQAAAcg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 09:48:25
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 05:48:18.355876 2026] [security2:error] [pid 12509:tid 12509] [client 172.71.118.186:12993] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sharkfamily.com"] [uri "/.git/config"] [unique_id "apFZYqSHoG-8yaefjkRvigAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 00:07:09
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:07:06.142995 2026] [security2:error] [pid 8507:tid 8507] [client 172.71.118.186:10902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zmgmt.com"] [uri "/.git/HEAD"] [unique_id "apDRKnBRkkPrwGKS8FwJ5wAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 04:20:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 00:20:35.645522 2026] [security2:error] [pid 3164280:tid 3164367] [client 172.71.118.186:13190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.petrovicimagery.com"] [uri "/.git/HEAD"] [unique_id "ao5pk7P5Pd-_fpWxKZzD3gAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 21:55:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 17:55:25.993799 2026] [security2:error] [pid 1881:tid 1881] [client 172.71.118.186:12748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.aoklandco.com"] [uri "/.git/config"] [unique_id "ao4PTXhiqIh3UJbq1HJbAgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 16:53:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 12:53:39.102563 2026] [security2:error] [pid 25194:tid 25194] [client 172.71.118.186:11138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.julienixon.com"] [uri "/.git/HEAD"] [unique_id "ao3Ik4W6qOltmIdp6D_CngAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-08-25 10:33:04
(1 week ago)
[TueAug2512:33:00.9014902026][security2:error][pid2355716:tid2355806][client172.71.118.186:0]ModSecu ...
show more
[TueAug2512:33:00.9014902026][security2:error][pid2355716:tid2355806][client172.71.118.186:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.pytag.ch\"][uri\"/.git/HEAD\"][unique_id\"ao1vXGCkhJpBYoS3jTgmxQAAAI8\"]
show less
Port Scan
Brute-Force
Web App Attack
π³π±
homeshowdomain.nl
2026-08-24 21:59:36
(1 week ago)
Auto-ban: >3000 req/min op 2026-08-24
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-24 12:43:35
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.118.186 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 08:43:28.760085 2026] [security2:error] [pid 11293:tid 11293] [client 172.71.118.186:13741] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "autodiscover.cwbaz.com"] [uri "/.git/HEAD"] [unique_id "aow8cHaRmDJZEs_DKiEvVAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·πΈ
iphouse
2026-08-24 09:30:03
(1 week ago)
Failed login attempt detected by Fail2Ban in plesk-apache jail
Web App Attack