๐บ๐ธ
TPI-Abuse
2026-10-09 01:51:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:51:02.500249 2026] [security2:error] [pid 16933:tid 16933] [client 23.81.230.221:46189] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shop.bwill.dev"] [uri "/.git/HEAD"] [unique_id "ashIhpWe3e2itaQZHEPUjQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 09:40:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:40:09.985195 2026] [security2:error] [pid 16754:tid 16754] [client 23.81.230.221:58702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nexthop.com"] [uri "/.git/HEAD"] [unique_id "asdk-XPSk4tC3uPBf8QJMAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:56:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:56:31.652082 2026] [security2:error] [pid 8572:tid 8572] [client 23.81.230.221:52127] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sfholidayrentals.com"] [uri "/.git/HEAD"] [unique_id "asb4T9BigXY84j2lCIsv9gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-08 01:49:06
(2 days ago)
[ThuOct0803:49:04.0753152026][security2:error][pid1665864:tid1665982][client23.81.230.221:0]ModSecur ...
show more
[ThuOct0803:49:04.0753152026][security2:error][pid1665864:tid1665982][client23.81.230.221:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"www.respiratrentino.it\"][uri\"/.git/HEAD/\"][unique_id\"asb2kMG3ZGvNKnAoVj-frgAAAlE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 00:10:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:10:22.903900 2026] [security2:error] [pid 27059:tid 27059] [client 23.81.230.221:43945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jacksonpropertyrentals.com"] [uri "/.git/HEAD"] [unique_id "asbfbtMwmoLvQaT1dtQBNgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-07 10:34:20
(2 days ago)
[Wed Oct 07 21:34:20.169974 2026] [security2:error] [pid 371657] [client 23.81.230.221:45403] [clien ...
show more
[Wed Oct 07 21:34:20.169974 2026] [security2:error] [pid 371657] [client 23.81.230.221:45403] [client 23.81.230.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "underconstruction.paulshipley.info"] [uri "/.git/HEAD"] [unique_id "asYgLGzUlgl8aucGo90iqQAAADg"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 13:45:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:45:06.512112 2026] [security2:error] [pid 13163:tid 13175] [client 23.81.230.221:33236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.afxindustries.com"] [uri "/.git/HEAD"] [unique_id "asT7YrwhdUrJVhFCsPB49AAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-06 13:09:22
(3 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 02:15:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 22:15:04.489677 2026] [security2:error] [pid 27415:tid 27415] [client 23.81.230.221:44044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.calicoinc.com"] [uri "/.git/HEAD"] [unique_id "ar8TqO0JgX8DaR-sJeY8iAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 12:49:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 08:49:34.364021 2026] [security2:error] [pid 7040:tid 7040] [client 23.81.230.221:37088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.adampayments.com"] [uri "/.git/HEAD"] [unique_id "arpiXu9LmMvkIAdvgXm3EwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 11:45:14
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 07:45:08.005504 2026] [security2:error] [pid 14903:tid 14948] [client 23.81.230.221:37911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.paywithfortress.com"] [uri "/.git/HEAD"] [unique_id "arpTRB6N5kMBHtZ_sStmBgAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 09:27:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 05:26:47.206958 2026] [security2:error] [pid 26227:tid 26227] [client 23.81.230.221:41212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "halloweenpartynapkins.piratecostumesonline.com"] [uri "/.git/HEAD"] [unique_id "aroy1xo4jpl3nXPlxUsa4gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-28 07:25:35
(1 week ago)
[mx02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Examp ...
show more
[mx02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 23.81.230.221 - - [28/Sep/2026:09:25:28 +0200] "GET /.git/HEAD HTTP/1.1" 301 162 "-" "Python-urllib/3.10"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 00:18:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 23.81.230.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 20:18:39.200024 2026] [security2:error] [pid 10339:tid 10339] [client 23.81.230.221:35050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.klingandi.com.bridgital.com"] [uri "/.git/HEAD"] [unique_id "arhg36XDWohzxB2FEjtyxQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-24 06:11:55
(2 weeks ago)
[24/Sep/2026:09:11:55 +0300] -- 23.81.230.221 Ban reason: User-Agent Python-urllib
Bad Web Bot
Web App Attack