๐บ๐ธ
TPI-Abuse
2026-08-31 20:29:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 16:29:42.149555 2026] [security2:error] [pid 15644:tid 15644] [client 172.71.232.98:14150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "puckerbuttbikinis.com"] [uri "/.git/config"] [unique_id "apXkNvsTKKwRbo1EGBiQcAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kkw
2026-08-31 14:06:40
(1 day ago)
[REDACTED] 172.71.232.98 - - [31/Aug/2026:16:06:39 +0200] "GET /.git/config HTTP/2.0" 404 3647 "-" " ...
show more
[REDACTED] 172.71.232.98 - - [31/Aug/2026:16:06:39 +0200] "GET /.git/config HTTP/2.0" 404 3647 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-30 17:21:32
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 13:41:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 09:40:58.135048 2026] [security2:error] [pid 7490:tid 7490] [client 172.71.232.98:14015] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.frenchla.com"] [uri "/.git/config"] [unique_id "apLham3pqR0VygFflZYLGgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 04:33:44
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:33:39.360287 2026] [security2:error] [pid 3562:tid 3581] [client 172.71.232.98:13030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.gelatoconsapevole.com"] [uri "/.git/config"] [unique_id "apJhI1ED9AO4Yy052C9vywAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-28 21:20:13
(4 days ago)
[FriAug2823:20:09.1757732026][security2:error][pid3193450:tid3193468][client172.71.232.98:0]ModSecur ...
show more
[FriAug2823:20:09.1757732026][security2:error][pid3193450:tid3193468][client172.71.232.98:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.domoticaswiss.ch\"][uri\"/.git/config\"][unique_id\"apH7iazro8tkk4-0svyyYwAAAAI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
CBJ
2026-08-28 20:54:56
(4 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:23:14
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:23:06.923912 2026] [security2:error] [pid 24311:tid 24311] [client 172.71.232.98:10915] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.lucid-hq.com"] [uri "/.git/config"] [unique_id "apHD-jjzPA2N0kAqUXOPXgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:48:07
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:48:01.938476 2026] [security2:error] [pid 2818:tid 2818] [client 172.71.232.98:10009] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bilimkurgumanyagi.com"] [uri "/.git/config"] [unique_id "apEhEWx0ENiwU6-pOqphngAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 04:32:07
(5 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-27 11:59:34
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:59:27.982818 2026] [security2:error] [pid 26727:tid 26727] [client 172.71.232.98:13834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hbgmccormickfoundation.org"] [uri "/.git/config"] [unique_id "apAmn1W4bDGmkhhD6CMmZgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 04:28:05
(6 days ago)
172.71.232.98 arduino.ua [27/Aug/2026:07:28:04 +0300] "GET /.git/config HTTP/2.0" 403 548 "-" "Mozil ...
show more
172.71.232.98 arduino.ua [27/Aug/2026:07:28:04 +0300] "GET /.git/config HTTP/2.0" 403 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36" 0.000 2388
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 13:53:13
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:53:09.582143 2026] [security2:error] [pid 51451:tid 51493] [client 172.71.232.98:9969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.exedesalesteam.com"] [uri "/.git/HEAD"] [unique_id "ao7vxXBXc4XiPuuTtUjuiAAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Grossmann-Gruppe
2026-08-26 06:38:19
(1 week ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-25 20:37:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 16:37:17.581026 2026] [security2:error] [pid 15428:tid 15428] [client 172.71.232.98:10185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.buggyshop.org"] [uri "/.git/config"] [unique_id "ao38_UpOX7XdopCGxdEf0QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack