๐บ๐ธ
TPI-Abuse
2026-08-20 23:58:03
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 19:57:57.717466 2026] [security2:error] [pid 9008:tid 9054] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a:12643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rubenluis.com"] [uri "/.git/config"] [unique_id "aoeUhbFixZUYkIrpf39O-wAAAgA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 13:30:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 09:30:09.877310 2026] [security2:error] [pid 29355:tid 29355] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a:9560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dceabronwilliams.com"] [uri "/.git/config"] [unique_id "aocBYdLcbGa0uQXE_BDT8gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 07:06:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 03:06:43.157444 2026] [security2:error] [pid 20175:tid 20175] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a:9910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cartiologyfilms.com"] [uri "/.git/HEAD"] [unique_id "aoang8plguD3A7a4WLcHkgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 00:54:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 20:54:16.412771 2026] [security2:error] [pid 28354:tid 28354] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a:11986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jspd.com"] [uri "/.git/HEAD"] [unique_id "aoT-uA_iVhp5us2raPledwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 23:48:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 19:48:24.789448 2026] [security2:error] [pid 27187:tid 27187] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a:14145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.laughingthunder.com"] [uri "/.git/HEAD"] [unique_id "aoTvSHDReEHxDhP5G2H31QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 02:15:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 22:15:05.555444 2026] [security2:error] [pid 3396:tid 3396] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a:13076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.familymailboxes.com"] [uri "/.git/config"] [unique_id "aoPAKaNAG1GG2yyz819O9gAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-07-01 14:25:33
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฏ๐ต
S.O.B.A. Dev.
2026-06-27 09:04:02
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฏ๐ต
S.O.B.A. Dev.
2026-05-15 09:48:57
(3 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-14 05:33:15
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 01:33:09.665622 2026] [security2:error] [pid 25641:tid 25641] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a:12043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mceldufftherapist.com"] [uri "/app/config/parameters.yml"] [unique_id "agVelZDeitfowy5QARP3jAAAAB4"], referer: https://www.google.com/search?q=mceldufftherapist.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-03 22:01:41
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-02.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2025-04-25 18:58:34
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 25 14:58:29.002141 2025] [security2:error] [pid 3434:tid 3434] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a:61160] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.istdergi.com"] [uri "/api/shared/.env"] [unique_id "aAvbVWYO2wPJXCMXJfy6yQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-15 03:30:05
(1 year ago)
| Multiple common web attacks from same source ip. (multiple servers)
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-05 03:39:34
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 04 23:39:30.351079 2025] [security2:error] [pid 429:tid 429] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a:11306] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redish.org"] [uri "/.env.test"] [unique_id "Z_Cl8q2DEIjA9hYtgfMnpwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-07 20:24:47
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:987:1000:cf21:a380:5ea5:210a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 07 15:24:40.660877 2025] [security2:error] [pid 506857:tid 506857] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a:62346] [client 2400:cb00:987:1000:cf21:a380:5ea5:210a] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hondabvi.com"] [uri "/.env.prod"] [unique_id "Z8tWCNdm7WC-NjAnHfLHTgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack