๐บ๐ธ
TPI-Abuse
2026-08-29 18:05:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 14:05:13.320334 2026] [security2:error] [pid 10757:tid 10757] [client 172.71.119.75:10295] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.phenoxcaribbean.com"] [uri "/.git/config"] [unique_id "apMfWcHo-4QNYGtx3Knn_AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 04:33:07
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:32:58.765258 2026] [security2:error] [pid 26207:tid 26207] [client 172.71.119.75:12106] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.motunaonaobookings.hamiltonbookings.com"] [uri "/.git/HEAD"] [unique_id "apJg-iTgL4bgfcX5LnJnawAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:53:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:53:46.638919 2026] [security2:error] [pid 5878:tid 5892] [client 172.71.119.75:12271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.aclarityforensics.com"] [uri "/.git/config"] [unique_id "apIRerTH8w7H2YU7V5vp-AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:00:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:00:36.933190 2026] [security2:error] [pid 24593:tid 24593] [client 172.71.119.75:9686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fanarch.xyz"] [uri "/.git/config"] [unique_id "apFqVGD5BUe5v8R3nhEszQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 04:33:58
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฉ๐ช
4server
2026-08-26 04:08:07
(5 days ago)
[WedAug2606:08:04.6490182026][security2:error][pid3396002:tid3396103][client172.71.119.75:0]ModSecur ...
show more
[WedAug2606:08:04.6490182026][security2:error][pid3396002:tid3396103][client172.71.119.75:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.jrtradeinnovation.ch\"][uri\"/.git/config\"][unique_id\"ao5mpLwB9gywzDF6sIT5bAAAAM8\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 18:43:09
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 14:43:02.714832 2026] [security2:error] [pid 10222:tid 10222] [client 172.71.119.75:14227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.register-yacht-germany.com"] [uri "/.git/HEAD"] [unique_id "ao3iNp5rca5zp4Zxx3DdDwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-25 11:24:16
(5 days ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-24 23:09:33
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 19:09:28.250154 2026] [security2:error] [pid 22080:tid 22080] [client 172.71.119.75:11660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tigerallenyim.com"] [uri "/.git/HEAD"] [unique_id "aozPKPvnOaRovWjBN28WwwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 08:19:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 04:19:13.588517 2026] [security2:error] [pid 14113:tid 14113] [client 172.71.119.75:10177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bienvenueplantation.cathrynn.com"] [uri "/.git/HEAD"] [unique_id "aoqtAT9Oah3nsoHOkpnpgwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 15:25:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 11:25:16.057566 2026] [security2:error] [pid 29236:tid 29236] [client 172.71.119.75:11490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.613.ninja"] [uri "/.git/HEAD"] [unique_id "aom_XB8lrbBBBYgyqap9sQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 16:10:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 12:10:14.986044 2026] [security2:error] [pid 20838:tid 20838] [client 172.71.119.75:12729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.southfloridachoppers.com"] [uri "/.git/config"] [unique_id "aoh4ZgTguL3_iyh2hS3DzQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 15:00:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 11:00:28.145835 2026] [security2:error] [pid 9690:tid 9690] [client 172.71.119.75:13670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.haco.rcto.us"] [uri "/.git/config"] [unique_id "aohoDLLXnXbRSJAssMiI7QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 12:55:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 08:55:23.555284 2026] [security2:error] [pid 6454:tid 6454] [client 172.71.119.75:10377] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.keepingitsharp.biz"] [uri "/.git/config"] [unique_id "aohKu-Mtc-67e7Hosjef_AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-20 22:16:35
(1 week ago)
[FriAug2100:16:27.2276802026][security2:error][pid2659896:tid2660194][client172.71.119.75:0]ModSecur ...
show more
[FriAug2100:16:27.2276802026][security2:error][pid2659896:tid2660194][client172.71.119.75:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"465\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"distributori-automatici-ticino.ch.cadvending.ch\"][uri\"/.git/HEAD\"][unique_id\"aod8uzrA6qlZgwqrXmn4VwAAARY\"]
show less
Hacking
Web App Attack