๐บ๐ธ
gerensat
2026-06-17 16:06:39
(1 day ago)
2026-06-17 13:06:39 | /.git/config | [] | Wget/1.21.3 (linux-gnu)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 05:02:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 01:02:51.924818 2026] [security2:error] [pid 10828:tid 10828] [client 172.71.148.149:12176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iostation.com"] [uri "/.git/config"] [unique_id "ajDY-87uGDNwBuu0iQvIBgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 10:22:20
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:22:12.125563 2026] [security2:error] [pid 30039:tid 30039] [client 172.71.148.149:9760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thalos.pe"] [uri "/.git/config"] [unique_id "ai6A1O1DHdZ2Qo0FHkeUhwAAAAo"], referer: https://www.google.com/search?q=thalos.pe
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 09:58:21
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 05:58:15.519409 2026] [security2:error] [pid 22620:tid 22620] [client 172.71.148.149:10572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "isyourcompanysafe.com.alanmariotti.com"] [uri "/.git/config"] [unique_id "ai0pt44eFWqCwvoGDaVVdAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-06-08 18:00:26
(1 week ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
webanyone
2026-06-08 17:30:27
(1 week ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฉ๐ช
webanyone
2026-06-05 14:30:24
(1 week ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
๐ณ๐ฑ
MM-bot
2026-06-04 14:11:45
(2 weeks ago)
URL-probe: HTTP/2 GET request on /.git/config (2026-06-04 16:11:45 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-04 04:51:15
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 00:51:09.661342 2026] [security2:error] [pid 14752:tid 14752] [client 172.71.148.149:13971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edenberg.com"] [uri "/.git/config"] [unique_id "aiEEPXWeTgqUi0cMOi9hJgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 19:33:59
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 15:33:55.116114 2026] [security2:error] [pid 5642:tid 5642] [client 172.71.148.149:12135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "northfortworthalliance.com"] [uri "/.git/config"] [unique_id "ah8wI0D4nOcVVk0xAFP5JAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 10:10:28
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:10:21.238327 2026] [security2:error] [pid 12024:tid 12024] [client 172.71.148.149:9610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "capitalacc.com"] [uri "/.git/config"] [unique_id "ah6sDaixFjON_KnVwxXjlwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-02 07:35:52
(2 weeks ago)
172.71.148.149 - - [02/Jun/2026:10:34:09 +0300] "GET /wp-content/uploads/ HTTP/1.1" 404 762 "-" "Moz ...
show more
172.71.148.149 - - [02/Jun/2026:10:34:09 +0300] "GET /wp-content/uploads/ HTTP/1.1" 404 762 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
172.71.148.149 - - [02/Jun/2026:10:35:51 +0300] "GET /wp-includes/customize/ HTTP/1.1" 404 762 "-" "Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 07:15:49
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 03:15:42.906084 2026] [security2:error] [pid 7382:tid 7399] [client 172.71.148.149:12954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "annefraser.com"] [uri "/.git/config"] [unique_id "ah6DHm9ZwAvzqpfyvuTH0gAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 01:56:12
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 21:56:07.965254 2026] [security2:error] [pid 21135:tid 21135] [client 172.71.148.149:11961] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scottschiaffo.com"] [uri "/.git/config"] [unique_id "ah44N_PARlZpNlwpJ_980wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-05-31 12:53:10
(2 weeks ago)
[SunMay3114:53:05.5362472026][security2:error][pid1163372:tid1163425][client172.71.148.149:0]ModSecu ...
show more
[SunMay3114:53:05.5362472026][security2:error][pid1163372:tid1163425][client172.71.148.149:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"flyingberber-finale.artisteer-italia.org\"][uri\"/.git/config\"][unique_id\"ahwvMfEjIsshCxcM4lN18wAAAFE\"]
show less
Port Scan
Brute-Force
Web App Attack