Anonymous
2026-10-01 07:30:09
(34 minutes ago)
[osotir.org] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 07:25:54
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 03:25:47.986780 2026] [security2:error] [pid 8224:tid 8224] [client 198.199.76.39:57362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web63.dnchosting.com"] [uri "/.git/config"] [unique_id "ar4K-yw9bem9HSsutK3awgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-10-01 06:34:10
(1 hour ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 198 ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 198.199.76.39 - - \[01/Oct/2026:08:34:03 +0200\] "GET /.git/config HTTP/1.1" 404 8025 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 06:32:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:32:05.340349 2026] [security2:error] [pid 24106:tid 24106] [client 198.199.76.39:41302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcsteven.com"] [uri "/.git/config"] [unique_id "ar3-ZZAgHXVrrwZ7pwD1pwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 06:02:17
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:02:09.863545 2026] [security2:error] [pid 22820:tid 22845] [client 198.199.76.39:59676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southtampaprinting.com"] [uri "/.git/config"] [unique_id "ar33YaT84SxTsfJHUnozbgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 05:33:48
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:33:41.537501 2026] [security2:error] [pid 30782:tid 30782] [client 198.199.76.39:57602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "providentbusinessllc.com"] [uri "/.git/config"] [unique_id "ar3wtWcBY5x_txNI-8rxfAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 05:11:13
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:11:08.783744 2026] [security2:error] [pid 426:tid 426] [client 198.199.76.39:44940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cypraea.info"] [uri "/.git/config"] [unique_id "ar3rbG9Vgcftg2EBZ8MAMwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 04:51:50
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.199.76.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:51:46.398520 2026] [security2:error] [pid 20582:tid 20582] [client 198.199.76.39:33236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hawaiivacations.com"] [uri "/.git/config"] [unique_id "ar3m4l_71uVbKU43K4l4_QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
syokadmin
2021-12-05 15:43:22
(4 years ago)
(mod_security) mod_security (id:225170) triggered by 198.199.76.39 (US/United States/-): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 198.199.76.39 (US/United States/-): 1 in the last 3600 secs
show less
Brute-Force
πΊπΈ
HJ5Ss4Ju
2021-12-05 10:13:20
(4 years ago)
Blocked by Wordfence (SID 1)
Web App Attack
πΊπΈ
tradenet
2021-12-04 21:56:19
(4 years ago)
198.199.76.39 - - [04/Dec/2021:20:56:08 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 ...
show more
198.199.76.39 - - [04/Dec/2021:20:56:08 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
198.199.76.39 - - [04/Dec/2021:20:56:09 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
198.199.76.39 - - [04/Dec/2021:20:56:10 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
198.199.76.39 - - [04/Dec/2021:20:56:11 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
198.199.76.39 - - [04/Dec/2021:20:56:12 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome
...
show less
Bad Web Bot
Web App Attack
Anonymous
2021-12-02 10:00:35
(4 years ago)
chaangnoifulda.de 198.199.76.39 [02/Dec/2021:16:00:34 +0100] "POST //xmlrpc.php HTTP/1.1" 200 683 "- ...
show more
chaangnoifulda.de 198.199.76.39 [02/Dec/2021:16:00:34 +0100] "POST //xmlrpc.php HTTP/1.1" 200 683 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
chaangnoifulda.de 198.199.76.39 [02/Dec/2021:16:00:34 +0100] "POST //xmlrpc.php HTTP/1.1" 200 5940 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Web App Attack
π©πͺ
ManagedStack
2021-12-02 05:56:36
(4 years ago)
Unauthorized path/IP Access (full log not revealed as it contains sensitive data)
Hacking
Web App Attack
πΊπΈ
MortimerCat
2021-12-02 02:17:09
(4 years ago)
Searching for renamed config files
Web App Attack
π²πΎ
syokadmin
2021-12-02 00:36:19
(4 years ago)
(mod_security) mod_security (id:225170) triggered by 198.199.76.39 (US/United States/-): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 198.199.76.39 (US/United States/-): 1 in the last 3600 secs
show less
Brute-Force