๐บ๐ธ
TPI-Abuse
2026-06-05 14:38:39
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:38:32.699162 2026] [security2:error] [pid 15238:tid 15238] [client 2602:f6f6:2:e74f::1:43856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.stinnetthomeinspection.com"] [uri "/.git/config"] [unique_id "aiLfaJVP7zE5R4Dj2AhuoAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 17:45:50
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 13:45:44.727225 2026] [security2:error] [pid 32502:tid 32502] [client 2602:f6f6:2:e74f::1:35790] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||cliniquecavalancia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cliniquecavalancia.com"] [uri "/back.sql"] [unique_id "af9yyIFY03o4qdVKZwfftgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:02:10
(2 months ago)
2026-04-26 08:00:29,234 fail2ban.actions [7718]: NOTICE [tor] Ban 2602:f6f6:2:e74f::1
2026-0 ...
show more
2026-04-26 08:00:29,234 fail2ban.actions [7718]: NOTICE [tor] Ban 2602:f6f6:2:e74f::1
2026-04-26 12:01:26,707 fail2ban.actions [7718]: NOTICE [tor] Ban 2602:f6f6:2:e74f::1
2026-04-26 18:01:24,487 fail2ban.actions [7718]: NOTICE [tor] Ban 2602:f6f6:2:e74f::1
2026-04-26 21:01:21,581 fail2ban.actions [7718]: NOTICE [tor] Ban 2602:f6f6:2:e74f::1
2026-04-27 00:02:09,347 fail2ban.actions [7718]: NOTICE [tor] Ban 2602:f6f6:2:e74f::1
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-16 11:33:24
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 07:33:16.330928 2026] [security2:error] [pid 3856519:tid 3856519] [client 2602:f6f6:2:e74f::1:46822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.phenoxcaribbean.com"] [uri "/en/.git/config"] [unique_id "aeDI_Ew7lrWGwhwH546gjgAAAAA"], referer: https://ipv6.phenoxcaribbean.com/.git/config
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-03-26 21:34:50
(3 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-23 20:13:07
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 15:12:58.322855 2026] [security2:error] [pid 17780:tid 17780] [client 2602:f6f6:2:e74f::1:36942] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dwightbrown.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dwightbrown.com"] [uri "/db_own.sql"] [unique_id "aZy0yujcJ1Nu0KP7j2ceQgAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 21:37:06
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 16:37:01.599336 2026] [security2:error] [pid 12807:tid 12807] [client 2602:f6f6:2:e74f::1:59022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.dadlounge.com"] [uri "/.git/config"] [unique_id "aZt2_doMppAeGzaWlZ5obAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 14:16:21
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 09:16:16.787498 2026] [security2:error] [pid 11220:tid 11233] [client 2602:f6f6:2:e74f::1:36574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.lcncmo.com"] [uri "/.git/config"] [unique_id "aZsPsIMU8jbrV9BKr7wSQAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 13:26:59
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:e74f::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 08:26:49.366587 2026] [security2:error] [pid 10665:tid 10799] [client 2602:f6f6:2:e74f::1:36612] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.reghay.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.reghay.com"] [uri "/re.sql"] [unique_id "aZsEGdmyr0g5n-UTfpA7mQAAAdA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-14 22:59:41
(4 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-02-13.
show less
Hacking
Web App Attack
SSH