πΊπΈ
TPI-Abuse
2026-08-28 14:40:13
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:40:10.471516 2026] [security2:error] [pid 6719:tid 6719] [client 172.71.118.204:11925] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cultureal.com"] [uri "/.git/config"] [unique_id "apGdyjDYTFArbaRcqVUNvwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 07:19:58
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:19:54.238086 2026] [security2:error] [pid 20657:tid 20657] [client 172.71.118.204:13690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mphq.net"] [uri "/.git/HEAD"] [unique_id "apE2mh4v6CoRPpUk8RzGewAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 22:17:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:17:36.110221 2026] [security2:error] [pid 3420422:tid 3420448] [client 172.71.118.204:9888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.siriuspharmaceuticals.com"] [uri "/.git/config"] [unique_id "apC3gHDMgArxPtEQ1zT0cgAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-08-27 02:42:16
(2 days ago)
[ThuAug2704:42:12.9179892026][security2:error][pid556049:tid556079][client172.71.118.204:0]ModSecuri ...
show more
[ThuAug2704:42:12.9179892026][security2:error][pid556049:tid556079][client172.71.118.204:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"kvsm-blackstone.com\"][uri\"/.git/HEAD\"][unique_id\"ao-kBHiKqfSKonf0U4dStwAAABM\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 07:09:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:09:21.510942 2026] [security2:error] [pid 15812:tid 15812] [client 172.71.118.204:9797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.healthydatasystems.com"] [uri "/.git/HEAD"] [unique_id "ao6RITp9UOVOXOfybN2O5wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
openstrike.co.uk
2026-08-26 05:16:25
(3 days ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
πΊπΈ
TPI-Abuse
2026-08-26 05:04:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:04:54.346730 2026] [security2:error] [pid 22747:tid 22747] [client 172.71.118.204:9380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.directnic-support.rocks"] [uri "/.git/HEAD"] [unique_id "ao5z9sBfyqN7MpG_6LzThwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Vegascosmetics
2026-08-25 14:50:28
(3 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: LOCALE-PROBE: Error404-LocalePath (/DE12984/.git/config)
show less
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 12:19:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:19:06.894798 2026] [security2:error] [pid 17515:tid 17515] [client 172.71.118.204:11075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "int.mavikalem.org"] [uri "/.git/HEAD"] [unique_id "ao2IOpErj27QmKBHo_PRigAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 11:42:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 07:42:30.759305 2026] [security2:error] [pid 31518:tid 31518] [client 172.71.118.204:11643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cs-mall.com"] [uri "/.git/config"] [unique_id "ao1_pq53r1ClKoPhd5VmNQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 10:05:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:05:35.033399 2026] [security2:error] [pid 3977:tid 3984] [client 172.71.118.204:11186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.love-spells-magic.com"] [uri "/.git/HEAD"] [unique_id "ao1o70fJdq_NBuwYx-6sVwAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-24 21:59:14
(4 days ago)
Auto-ban: >3000 req/min op 2026-08-24
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-24 14:00:05
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:59:56.149499 2026] [security2:error] [pid 4092:tid 4092] [client 172.71.118.204:13300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lbee.com"] [uri "/.git/config"] [unique_id "aoxOXGk_N3ZOuAJJpFReNgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alboweb B.V.
2026-08-24 11:11:03
(4 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 15:02:38
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:02:31.358086 2026] [security2:error] [pid 20941:tid 20941] [client 172.71.118.204:10025] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.book-runningonempty.com"] [uri "/.git/HEAD"] [unique_id "aosLh8Q8Qvwf8Q9Rdxu8OgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack