๐บ๐ธ
TPI-Abuse
2026-10-11 08:26:12
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 11 04:26:06.880484 2026] [security2:error] [pid 12002:tid 12010] [client 198.46.199.29:51144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mecconsultant.com"] [uri "/.git/HEAD"] [unique_id "astIHuwNL4syr8kynnnVWQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Roper123
2026-10-11 06:08:53
(6 hours ago)
Web app exploits
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 09:39:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:39:03.962808 2026] [security2:error] [pid 12602:tid 12602] [client 198.46.199.29:47114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ourwalkwithgod.com.player-care.com"] [uri "/.git/HEAD"] [unique_id "asdkt_jWnA8PYO5ZFU3EKgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:56:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:56:31.528812 2026] [security2:error] [pid 14458:tid 14458] [client 198.46.199.29:35267] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sfholidayrentals.com"] [uri "/.git/HEAD"] [unique_id "asb4T7A2wh8g1K8F60sHvwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:55:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:55:27.998839 2026] [security2:error] [pid 7372:tid 7379] [client 198.46.199.29:49494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gilesrentalcars.com"] [uri "/.git/HEAD"] [unique_id "asbb70TFJH4EBjWSbcIRPgAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-07 10:34:20
(4 days ago)
[Wed Oct 07 21:34:20.173262 2026] [security2:error] [pid 371642] [client 198.46.199.29:40214] [clien ...
show more
[Wed Oct 07 21:34:20.173262 2026] [security2:error] [pid 371642] [client 198.46.199.29:40214] [client 198.46.199.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/.git/HEAD"] [unique_id "asYgLBK8MwZJIy1xD2mkTwAAACk"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 09:31:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:31:05.421652 2026] [security2:error] [pid 8699:tid 8699] [client 198.46.199.29:46146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.urbnet.com"] [uri "/.git/HEAD"] [unique_id "asYRWYg9KSYPRqJ71g_-5AAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-03 15:28:12
(1 week ago)
Secret file probe | method: GET | path: /.git/HEAD | ua: Python-urllib/3.10
Hacking
Web App Attack
Anonymous
2026-10-03 09:04:55
(1 week ago)
Web probing (1 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CR ...
show more
Web probing (1 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 09:27:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 05:26:48.749756 2026] [security2:error] [pid 23066:tid 23066] [client 198.46.199.29:58861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chickenchristmascards.com.piratecostumesonline.com"] [uri "/.git/HEAD"] [unique_id "aroy2CA1tye9dw-HBwrRPgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
FreeMyIP
2026-09-23 21:55:31
(2 weeks ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 14:35:40
(2 weeks ago)
[23/Sep/2026:17:35:40 +0300] -- 198.46.199.29 Ban reason: User-Agent Python-urllib
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 07:46:22
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 03:46:14.168744 2026] [security2:error] [pid 24246:tid 24246] [client 198.46.199.29:44024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pamplonaserviciotecnico.ayudaclic.com"] [uri "/.git/HEAD"] [unique_id "arODxurZHObXtx9j_e7IhAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-21 22:03:45
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-20.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 23:48:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.46.199.29 (198-46-199-29-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:48:53.173155 2026] [security2:error] [pid 30878:tid 30878] [client 198.46.199.29:56101] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "todotex.com"] [uri "/.git/HEAD"] [unique_id "arBw5SxWnHYqtu_m9p2ViwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack