๐ณ๐ฑ
BlueWire Hosting
2026-08-29 23:43:58
(14 minutes ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-29 09:14:16
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:28:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:27:52.797167 2026] [security2:error] [pid 6856:tid 6856] [client 172.71.232.28:11700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "countertop.mooseled.com"] [uri "/.git/config"] [unique_id "apHTKCall9GAe6s_Sb1h2AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 13:44:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:44:20.183845 2026] [security2:error] [pid 10018:tid 10018] [client 172.71.232.28:9835] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "simplybrandedllc.com"] [uri "/.git/HEAD"] [unique_id "apGQtC15IONRjrVVV1cC7wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Little Iguana
2026-08-28 02:29:24
(1 day ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 00:58:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:58:05.704895 2026] [security2:error] [pid 21318:tid 21318] [client 172.71.232.28:12793] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aemcmullin.com"] [uri "/.git/config"] [unique_id "apDdHZaKzZIWnEfRTBVClgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
kumiko
2026-08-27 08:01:34
(2 days ago)
[2026-08-27 11:01:33] Probing for dotfiles
"GET /.git/HEAD HTTP/2.0" 301
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 03:12:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:12:46.722259 2026] [security2:error] [pid 19090:tid 19098] [client 172.71.232.28:10756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.michaelrandon.com"] [uri "/.git/HEAD"] [unique_id "ao-rLt0rQeUWUKJiCiUoRQAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:53:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:53:30.929812 2026] [security2:error] [pid 557414:tid 557418] [client 172.71.232.28:13170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.1shot.us"] [uri "/.git/config"] [unique_id "ao82KvBb9xgo68TKuiqDrQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-26 18:08:35
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 00:25:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 20:25:47.764695 2026] [security2:error] [pid 2792:tid 2792] [client 172.71.232.28:13201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.boardingatthewedge.com"] [uri "/.git/config"] [unique_id "ao4yi0kNgVej9Y2WAmU71QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 20:17:38
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 16:17:32.395600 2026] [security2:error] [pid 20891:tid 20891] [client 172.71.232.28:14117] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sutherlandyogastudio.com"] [uri "/.git/config"] [unique_id "ao34XFP2aJhPeYyDUqsFPwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 19:50:57
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 15:50:52.418127 2026] [security2:error] [pid 18855:tid 18855] [client 172.71.232.28:12078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tv.grancanariaholidays.com"] [uri "/.git/HEAD"] [unique_id "aoygnO-gWEpgSUrkNxCBKwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 16:47:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 12:47:46.594880 2026] [security2:error] [pid 29946:tid 29946] [client 172.71.232.28:13270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intrinsicartstudios.crossfiregold.com"] [uri "/.git/HEAD"] [unique_id "aox1shaO5ovwGCagTudOXQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 05:14:57
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 01:14:51.081504 2026] [security2:error] [pid 23760:tid 23760] [client 172.71.232.28:10365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.berkelmiami.com"] [uri "/.git/config"] [unique_id "aovTS1tczKHR_muT93742AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack