🇺🇸
TPI-Abuse
2026-09-09 21:26:51
(5 minutes ago)
(mod_security) mod_security (id:210492) triggered by 172.86.74.223 (223.74.86.172.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.74.223 (223.74.86.172.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 17:26:47.341622 2026] [security2:error] [pid 13355:tid 13355] [client 172.86.74.223:60014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.altruaglobalsolutions.com"] [uri "/.git/config"] [unique_id "aqHPF65T0p-1FrC7U_eHpwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
kkw
2026-09-09 21:17:56
(14 minutes ago)
[REDACTED] 172.86.74.223 - - [09/Sep/2026:23:17:55 +0200] "GET /.git/config HTTP/1.1" 302 4550 "-" " ...
show more
[REDACTED] 172.86.74.223 - - [09/Sep/2026:23:17:55 +0200] "GET /.git/config HTTP/1.1" 302 4550 "-" "Mozilla/5.0 (X11; Linux x86_64)"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇩🇪
iNetWorker
2026-09-09 21:05:07
(27 minutes ago)
trolling for resource vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 20:49:36
(43 minutes ago)
(mod_security) mod_security (id:210492) triggered by 172.86.74.223 (223.74.86.172.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.74.223 (223.74.86.172.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 16:49:31.451848 2026] [security2:error] [pid 572:tid 572] [client 172.86.74.223:59926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stefchild.com"] [uri "/.git/config"] [unique_id "aqHGW-MlPb4k_NoO269p_gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-09-09 20:19:57
(1 hour ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.86.74.223 (US/United States/223 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.86.74.223 (US/United States/223.74.86.172.static.cloudzy.com): 1 in the last 3600 secs
show less
Web App Attack
🇩🇪
big-cloud.nl
2026-09-09 20:09:53
(1 hour ago)
Try to access /.git/config
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 19:30:25
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.86.74.223 (223.74.86.172.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.74.223 (223.74.86.172.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 15:30:17.825936 2026] [security2:error] [pid 29228:tid 29228] [client 172.86.74.223:41350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "visithastingsvillage.com"] [uri "/.git/config"] [unique_id "aqGzySEUVZcvX6MtmyaJZwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
joharikop
2026-09-09 19:21:43
(2 hours ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 19:14:31
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.86.74.223 (223.74.86.172.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.74.223 (223.74.86.172.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 15:14:25.390901 2026] [security2:error] [pid 8020:tid 8020] [client 172.86.74.223:46918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kcmastercleaners.com"] [uri "/.git/config"] [unique_id "aqGwEbv16x1WfNt7ZqfoFgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 19:12:58
(2 hours ago)
GET /.git/config HTTP/1.1
...
Web App Attack
🇺🇸
Vano Ganzzz
2026-09-09 19:06:20
(2 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 14956 (RouterHosting LLC ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 14956 (RouterHosting LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-09-09T19:06:20Z
Ray ID: a38878374e84937c
UA: Mozilla/5.0 (X11; Linux x86_64)
show less
Bad Web Bot
🇨🇦
TechnoSolutions CL
2026-09-09 18:47:04
(2 hours ago)
172.86.74.223 - - [09/Sep/2026:15:33:45 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X ...
show more
172.86.74.223 - - [09/Sep/2026:15:33:45 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64)"
172.86.74.223 - - [09/Sep/2026:18:35:08 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64)"
172.86.74.223 - - [09/Sep/2026:18:47:03 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
gumbysoft
2026-09-09 18:38:05
(2 hours ago)
Unauthorized web vulnerability scan (/.env, wordpress, etc.)
Web App Attack
🇩🇪
ghostwarriors
2026-09-09 18:20:12
(3 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-09 18:15:53
(3 hours ago)
172.86.74.223 - - [09/Sep/2026:19:11:59 +0200] "GET /.git/config HTTP/1.1" 403 4441 "-" "Mozilla/5.0 ...
show more
172.86.74.223 - - [09/Sep/2026:19:11:59 +0200] "GET /.git/config HTTP/1.1" 403 4441 "-" "Mozilla/5.0 (X11; Linux x86_64)"
172.86.74.223 - - [09/Sep/2026:18:15:21 +0200] "GET /.git/config HTTP/1.1" 403 4440 "-" "Mozilla/5.0 (X11; Linux x86_64)"
172.86.74.223 - - [09/Sep/2026:20:15:50 +0200] "GET /.git/config HTTP/1.1" 403 4432 "-" "Mozilla/5.0 (X11; Linux x86_64)"
show less
Web App Attack
Hacking