๐บ๐ธ
TPI-Abuse
2026-09-18 08:26:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 04:26:13.243047 2026] [security2:error] [pid 22497:tid 22497] [client 172.71.232.24:12411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biblicalartifact.com.dinogirl.com"] [uri "/.git/config"] [unique_id "aqz1pRhQaO5M4CvqO6MzuAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-18 03:15:05
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ง๐ท
paradoxnetworks
2026-09-17 12:18:38
(2 days ago)
2026-09-17T12:13:35.683638+00:00 edge-con-sao01.int.pdx.net.uk sshd-session[975309]: pam_unix(sshd:a ...
show more
2026-09-17T12:13:35.683638+00:00 edge-con-sao01.int.pdx.net.uk sshd-session[975309]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=172.71.232.24
2026-09-17T12:13:37.767744+00:00 edge-con-sao01.int.pdx.net.uk sshd-session[975309]: Failed password for invalid user pi from 172.71.232.24 port 64787 ssh2
2026-09-17T12:18:38.166045+00:00 edge-con-sao01.int.pdx.net.uk sshd-session[976265]: Invalid user moxa from 172.71.232.24 port 64462
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-01 03:13:51
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:13:43.481487 2026] [security2:error] [pid 14566:tid 14566] [client 172.71.232.24:14186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "syconline.com"] [uri "/.git/config"] [unique_id "apZC5-bEv0bnMMpKF1fJagAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 07:53:56
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 03:53:50.744036 2026] [security2:error] [pid 13952:tid 13952] [client 172.71.232.24:10489] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paguilar.com"] [uri "/.git/config"] [unique_id "apPhjh2MxfiHuE1ZlsMo6wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 13:25:30
(3 weeks ago)
GET /.git/config HTTP/1.1
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:48:29
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:48:24.730429 2026] [security2:error] [pid 24278:tid 24278] [client 172.71.232.24:13035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thehomzasson.andrsn.com"] [uri "/.git/config"] [unique_id "apF1iBxT-c-YFdi-KtzHJQAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 00:47:33
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 22:48:16
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 18:48:11.201442 2026] [security2:error] [pid 5538:tid 5538] [client 172.71.232.24:9801] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.corangues.com"] [uri "/.git/HEAD"] [unique_id "ao9tK1zS974_DqZk1d9jWQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 22:05:11
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 18:05:03.835556 2026] [security2:error] [pid 1023555:tid 1023667] [client 172.71.232.24:11220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.promc.xyz"] [uri "/.git/HEAD"] [unique_id "ao9jD0Rz8FzfNC9SV3BSLQAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 01:44:31
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 21:44:28.375341 2026] [security2:error] [pid 12444:tid 12444] [client 172.71.232.24:12242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nationalnova.com.sprektech.com"] [uri "/.git/HEAD"] [unique_id "ao5E_PKBTm9YZqvc1kIVTAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 20:01:10
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 16:01:03.176880 2026] [security2:error] [pid 19853:tid 19865] [client 172.71.232.24:9649] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.secondsundayseriesecc.org"] [uri "/.git/config"] [unique_id "ao30f0RrOHsIoOj-ZfPMTQAAAgc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-25 04:22:36
(3 weeks ago)
[25/Aug/2026:07:22:35 +0300] -- 172.71.232.24 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[25/Aug/2026:07:22:35 +0300] -- 172.71.232.24 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 00:32:27
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 20:32:20.531726 2026] [security2:error] [pid 23481:tid 23481] [client 172.71.232.24:12507] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ilanknapp.com"] [uri "/.git/HEAD"] [unique_id "aouRFOf5lnBQPzHMZZWjTwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-23 14:50:05
(3 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack