๐ฏ๐ต
S.O.B.A. Dev.
2026-08-31 10:41:21
(4 days ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-08-31 03:21:24
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 20:37:48
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 16:37:42.026133 2026] [security2:error] [pid 9294:tid 9294] [client 172.71.232.154:11142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.offbeatcompassion.com"] [uri "/.git/config"] [unique_id "apNDFpr7d_KujbzEUVPY5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 16:28:06
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 12:28:00.917621 2026] [security2:error] [pid 19857:tid 19857] [client 172.71.232.154:12243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.deniz-bilgisayar.com"] [uri "/.git/config"] [unique_id "apMIkNtXQCEwFXY7Dq1MXwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-29 12:43:44
(6 days ago)
[SatAug2914:43:42.4006452026][security2:error][pid4083984:tid4084162][client172.71.232.154:0]ModSecu ...
show more
[SatAug2914:43:42.4006452026][security2:error][pid4083984:tid4084162][client172.71.232.154:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.agilityrossoblu.ch\"][uri\"/.git/config\"][unique_id\"apLT_r3XxPqalu1gRYrx7AAAARM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:57:23
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:57:14.755199 2026] [security2:error] [pid 19061:tid 19061] [client 172.71.232.154:14074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.stacyfarm.com"] [uri "/.git/config"] [unique_id "apHaCqGpSCuhNiGDh-HMMQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 06:38:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:38:16.447289 2026] [security2:error] [pid 1099:tid 1099] [client 172.71.232.154:11714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lauranixon.com"] [uri "/.git/config"] [unique_id "apEs2FwNTqfl5-nDTVpdtAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 02:33:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 22:33:13.029603 2026] [security2:error] [pid 31020:tid 31020] [client 172.71.232.154:9833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.grupoimaginarte.com"] [uri "/.git/config"] [unique_id "apDzaacyS-DlRuFS8tBRIQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 04:46:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:46:38.053200 2026] [security2:error] [pid 15495:tid 15495] [client 172.71.232.154:11296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.reettaanttila.com"] [uri "/.git/config"] [unique_id "ao_BLu5_nAlWM2zAt4WzhwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 03:46:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:45:59.556368 2026] [security2:error] [pid 27144:tid 27144] [client 172.71.232.154:10827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aquatech-ind.com"] [uri "/.git/config"] [unique_id "ao-y92YSyfJNZ9LJh7LIngAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 00:59:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 20:59:31.923937 2026] [security2:error] [pid 11549:tid 11549] [client 172.71.232.154:12228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.icbsmonitor.net"] [uri "/.git/config"] [unique_id "ao-L81KDKCKV2WkV98fTUwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 15:13:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 11:13:33.498762 2026] [security2:error] [pid 16780:tid 16780] [client 172.71.232.154:12538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caravaningfigaro.com"] [uri "/.git/config"] [unique_id "ao8CnR6usU3jU1ZLe1F3jgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 12:31:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:31:49.307919 2026] [security2:error] [pid 84423:tid 84427] [client 172.71.232.154:12270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.daraluz.net"] [uri "/.git/config"] [unique_id "ao7ctYia_pCg3DDvs79hDQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 21:07:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 17:06:56.002660 2026] [security2:error] [pid 17938:tid 17940] [client 172.71.232.154:10004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "birdhousefarms.com"] [uri "/.git/config"] [unique_id "ao4D8He4nqFn3WvMfOw8MwAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 16:07:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 12:07:40.702680 2026] [security2:error] [pid 20385:tid 20385] [client 172.71.232.154:13441] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dannyvanrijswijk.com"] [uri "/.git/HEAD"] [unique_id "aoxsTAUju1EHjfhUeLiwxQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack