๐ฉ๐ช
4server
2026-08-29 08:13:06
(2 hours ago)
[SatAug2910:12:59.7652522026][security2:error][pid3824853:tid3824923][client172.71.118.244:0]ModSecu ...
show more
[SatAug2910:12:59.7652522026][security2:error][pid3824853:tid3824923][client172.71.118.244:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.autoeuro.lv\"][uri\"/.git/HEAD\"][unique_id\"apKUi1Xzq05EldWCKbdEKwAAAIA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 04:32:43
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:32:38.434626 2026] [security2:error] [pid 29804:tid 29820] [client 172.71.118.244:10805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cynthiawilson.net"] [uri "/.git/config"] [unique_id "apJg5mUNw_Pa5vbYVDvsMwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-28 08:30:33
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 08:18:23
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 04:18:14.950657 2026] [security2:error] [pid 29655:tid 29655] [client 172.71.118.244:11371] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.likulikubookings.com"] [uri "/.git/config"] [unique_id "apFERv1kmp-9lvfXQBGMjwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 07:51:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:50:57.949785 2026] [security2:error] [pid 23048:tid 23048] [client 172.71.118.244:9723] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.touchmypython.bwill.dev"] [uri "/.git/config"] [unique_id "apE94cBye7s1e7dbLJVmngAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-26 15:39:00
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-26 04:12:11
(3 days ago)
[26/Aug/2026:07:12:11 +0300] -- 172.71.118.244 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[26/Aug/2026:07:12:11 +0300] -- 172.71.118.244 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 18:32:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 14:32:00.249020 2026] [security2:error] [pid 27161:tid 27161] [client 172.71.118.244:10983] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.register-yacht-greece.com"] [uri "/.git/HEAD"] [unique_id "ao3foP9pDcF79o88NT2pUwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 08:06:29
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 04:06:20.098033 2026] [security2:error] [pid 17100:tid 17100] [client 172.71.118.244:9459] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.artworkbyjen.hatfulofrain.com"] [uri "/.git/HEAD"] [unique_id "ao1M_OiUTaki5hJmDI4ReQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 17:12:42
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 13:12:33.467652 2026] [security2:error] [pid 28632:tid 28632] [client 172.71.118.244:12596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.anthonyanimalclinic.net"] [uri "/.git/HEAD"] [unique_id "aox7gQYT7P5q6iYWywBhyQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 16:20:20
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 12:20:12.451805 2026] [security2:error] [pid 26243:tid 26243] [client 172.71.118.244:11623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medusakenya.com"] [uri "/.git/HEAD"] [unique_id "aoxvPMyfUApDVPXA3KBoXAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
beon
2026-08-24 06:59:48
(5 days ago)
[DateTime=>2026-08-24T06:59:48Z (UTC)] , [HoneyPot_Hit=>once] , [HoneyPot=>/.git/config] , [total_Hi ...
show more
[DateTime=>2026-08-24T06:59:48Z (UTC)] , [HoneyPot_Hit=>once] , [HoneyPot=>/.git/config] , [total_Hit=>once]
show less
Bad Web Bot
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-24 04:23:58
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:23:50.560631 2026] [security2:error] [pid 27723:tid 27723] [client 172.71.118.244:11679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hal.digital"] [uri "/.git/config"] [unique_id "aovHVr7HBxmFIvrT79AyQQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 02:31:45
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.118.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 22:31:39.464250 2026] [security2:error] [pid 14416:tid 14416] [client 172.71.118.244:10312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.salinabible.org"] [uri "/.git/HEAD"] [unique_id "aoutCxK07-ylfCDO-Oa61wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-23 22:01:30
(5 days ago)
[24/Aug/2026:01:01:29 +0300] -- 172.71.118.244 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[24/Aug/2026:01:01:29 +0300] -- 172.71.118.244 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack