๐ช๐ธ
el-brujo
2026-08-29 05:09:37
(22 hours ago)
29/Aug/2026:07:09:37.343742 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
29/Aug/2026:07:09:37.343742 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.71.124.240] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /../ found within REQUEST_URI_RAW: /_next/../.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "www.el-hacker.org"] [uri "/.env"] [unique_id "apJpked-wcKBhG5ggRmtwAAkqjE"]
...
show less
Hacking
Web App Attack
๐ฌ๐ง
ISPLtd
2026-08-17 09:20:19
(1 week ago)
172.71.124.240 - - [17/Aug/2026:06:20:19 -0300] "GET /.git/HEAD
172.71.124.240 - - [17/Aug/2026:06:2 ...
show more
172.71.124.240 - - [17/Aug/2026:06:20:19 -0300] "GET /.git/HEAD
172.71.124.240 - - [17/Aug/2026:06:20:19 -0300] "GET /.git/config
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:58:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:58:15.346954 2026] [security2:error] [pid 1758:tid 1798] [client 172.71.124.240:10580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marinkovich.org"] [uri "/.git/HEAD"] [unique_id "aoK_F8bHfhT1DYlLVDvOggAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:03:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:02:59.067034 2026] [security2:error] [pid 26940:tid 26940] [client 172.71.124.240:11989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.atsllc.biz"] [uri "/.git/config"] [unique_id "aoKyI12mjvi0lQinw-5tdQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:48:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:48:37.830346 2026] [security2:error] [pid 8432:tid 8432] [client 172.71.124.240:10738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jonnyonthespot.biz"] [uri "/.git/config"] [unique_id "aoKgtRyK7LfQLOBVqLyILQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 04:36:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 00:36:53.098284 2026] [security2:error] [pid 10864:tid 10878] [client 172.71.124.240:9331] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.n5brg.com"] [uri "/.git/config"] [unique_id "aoKP5UJPM9tA3yduzl1taQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:26:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:26:31.055607 2026] [security2:error] [pid 1619:tid 1619] [client 172.71.124.240:11914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.madburylibrary.org"] [uri "/.git/HEAD"] [unique_id "aoJ_Z7ZGjN9itDqxKtVkEAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 00:39:30
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 20:39:23.800773 2026] [security2:error] [pid 20671:tid 20671] [client 172.71.124.240:12675] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "freedrm.org"] [uri "/.git/HEAD"] [unique_id "aoJYOxjSDlZ5pbbCAQA80gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 00:06:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 20:06:03.004589 2026] [security2:error] [pid 5384:tid 5384] [client 172.71.124.240:12745] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gcchsa.org"] [uri "/.git/HEAD"] [unique_id "aoJQa2J48gdNkXMMWSgbDwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 22:39:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:39:47.596249 2026] [security2:error] [pid 11139:tid 11226] [client 172.71.124.240:9746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gotlib.net"] [uri "/.git/config"] [unique_id "aoI8M3tlcMtAbgUWn8sHjQAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:43:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:43:14.878678 2026] [security2:error] [pid 20424:tid 20424] [client 172.71.124.240:9338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.greybird.cc"] [uri "/.git/config"] [unique_id "aoFqEnzp-SpR9FaRpzfM_QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 04:46:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:46:08.946485 2026] [security2:error] [pid 15282:tid 15282] [client 172.71.124.240:13639] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.crescendostage.com"] [uri "/.git/config"] [unique_id "aoFAkE7B2JUuYABEIr8B1QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:55:11
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:55:03.740691 2026] [security2:error] [pid 9418:tid 9418] [client 172.71.124.240:10603] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ohanameetup.party"] [uri "/.git/config"] [unique_id "aoE0lw25s-4Hvwo_oXNhhQAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 13:42:30
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 09:42:22.176710 2026] [security2:error] [pid 4804:tid 4804] [client 172.71.124.240:10929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wilcoxlawllc.com"] [uri "/.git/config"] [unique_id "aoBsvo49WxClbERtlMfhBAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 01:46:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.124.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 21:46:17.330372 2026] [security2:error] [pid 1082195:tid 1082243] [client 172.71.124.240:10877] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.broadmoordermatology.com"] [uri "/.git/HEAD"] [unique_id "an0h6ajJXA626sezZoWerwAAAgg"]
show less
Brute-Force
Bad Web Bot
Web App Attack