๐บ๐ธ
TPI-Abuse
2026-08-21 17:48:47
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 13:48:41.221354 2026] [security2:error] [pid 4175:tid 4175] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:9322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.joyfulservice.com"] [uri "/.git/config"] [unique_id "aoiPeZm8XxGxJ4cwS9Y3uQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 10:59:26
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 06:59:21.091938 2026] [security2:error] [pid 6107:tid 6107] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:11519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.km-herbs.com"] [uri "/.git/config"] [unique_id "aogviRR9qHTiMDSN49dIbAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 06:57:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 02:57:30.323841 2026] [security2:error] [pid 4753:tid 4788] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:9800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.bhsclassof68.info"] [uri "/.git/HEAD"] [unique_id "aof22j3MrDZHM9V5kuwi5QAAAYI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 23:54:14
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 19:54:09.664885 2026] [security2:error] [pid 5193:tid 5222] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:11706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.southsideeconomic.org"] [uri "/.git/HEAD"] [unique_id "aoeToe0MaQMQkYNqLMV6ogAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 22:50:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 18:50:46.033773 2026] [security2:error] [pid 20961:tid 20961] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:10919] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ardecymusic.com"] [uri "/.git/HEAD"] [unique_id "aoYzRnpFwkHLi08VfAbobQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 01:37:32
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:37:25.379161 2026] [security2:error] [pid 27785:tid 27785] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:13483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hudswell.com"] [uri "/.git/config"] [unique_id "aoO3VZqSHdX4cYJYzFPr8gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-06-23 13:43:57
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-17 22:02:40
(2 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-16.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2025-05-28 02:48:59
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 27 22:48:54.122470 2025] [security2:error] [pid 1222487:tid 1222487] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:46602] [client 2400:cb00:532:1000:2b92:131e:116:4b7e] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hvacs-aircon.com"] [uri "/.env.staging"] [unique_id "aDZ5ljqe5u6hLTBAneyZcwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-30 06:52:40
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 02:52:35.913981 2025] [security2:error] [pid 18150:tid 18150] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:21758] [client 2400:cb00:532:1000:2b92:131e:116:4b7e] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pixacast.com"] [uri "/public/.env"] [unique_id "aBHIs602F8evpaTHnlE_KQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-26 20:36:21
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 26 16:36:16.802411 2025] [security2:error] [pid 803812:tid 803812] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:32344] [client 2400:cb00:532:1000:2b92:131e:116:4b7e] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.rodrigoaldecoa.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.rodrigoaldecoa.com"] [uri "/db.ini"] [unique_id "aA1DwPqQ_uiAEHbUxO1q2wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-26 18:59:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 26 14:59:49.713824 2025] [security2:error] [pid 2774:tid 2774] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:11442] [client 2400:cb00:532:1000:2b92:131e:116:4b7e] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.redish.org"] [uri "/app/config/.env"] [unique_id "aA0tJQKPpWZgWmbftWiHRAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-08 16:21:16
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:240335) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 08 11:21:13.046117 2025] [security2:error] [pid 2421847:tid 2421847] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:39730] [client 2400:cb00:532:1000:2b92:131e:116:4b7e] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 146.70.184.103 (+1 hits since last alert)|rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rodrigoaldecoa.com"] [uri "/xmlrpc.php"] [unique_id "Z6eEeQF77L1PxQMTl9HbxgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-24 23:31:43
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 24 18:31:40.279690 2025] [security2:error] [pid 15161:tid 15161] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:44908] [client 2400:cb00:532:1000:2b92:131e:116:4b7e] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/dev/.env"] [unique_id "Z5Qi3H76oY6TDceoRw3r4gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-19 15:01:12
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown) ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:532:1000:2b92:131e:116:4b7e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 19 10:01:07.376323 2024] [security2:error] [pid 27517:tid 27517] [client 2400:cb00:532:1000:2b92:131e:116:4b7e:36584] [client 2400:cb00:532:1000:2b92:131e:116:4b7e] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avaliantlife.com"] [uri "/.env.bak"] [unique_id "Z2Q1MymobtqfPs1Z5f3AnQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack