๐บ๐ธ
TPI-Abuse
2026-09-30 04:43:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:43:43.720718 2026] [security2:error] [pid 14568:tid 14568] [client 2a02:6ea0:1508:6::d001:45468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "renjunews.com"] [uri "/.git/index"] [unique_id "aryTf9BF7n877BmJMZCItwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
Renรฉ Hickersberger
2026-09-30 04:42:34
(4 days ago)
malicious bot detected: violations="hit-honeypot"; user_agent="moving-to-bins/1.0"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:02:20
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:02:16.192588 2026] [security2:error] [pid 14833:tid 14833] [client 2a02:6ea0:1508:6::d001:33454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "recetabook.com"] [uri "/.git/index"] [unique_id "aryJyLDQ1TnqZ2z_MxMkiQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
0d0a
2026-09-30 03:02:57
(4 days ago)
Automated brute-force report from Fail2Ban
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 01:06:10
(4 days ago)
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:6ea0:1508:6::d001 - - [30/Sep/2026:03:05:57 +0200] "GET /.git/index HTTP/2.0" 404 1920 "-" "moving-to-bins/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:09:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:09:38.684740 2026] [security2:error] [pid 11414:tid 11414] [client 2a02:6ea0:1508:6::d001:50522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portalvasco.com"] [uri "/.git/index"] [unique_id "arxTQmU4WU_MseBWR1JNHwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 21:16:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:16:15.914391 2026] [security2:error] [pid 26097:tid 26097] [client 2a02:6ea0:1508:6::d001:52884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pcsyportatiles.com"] [uri "/.git/index"] [unique_id "arwqn6W5iFNFJFrroWHZOQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:04:06
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:03:57.925282 2026] [security2:error] [pid 31186:tid 31186] [client 2a02:6ea0:1508:6::d001:42124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pakistanvision.com"] [uri "/.git/index"] [unique_id "arwZrbFRagJU-_4ISKUf1AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 16:35:21
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 12:35:16.045791 2026] [security2:error] [pid 10992:tid 10992] [client 2a02:6ea0:1508:6::d001:58596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nowell.net"] [uri "/.git/index"] [unique_id "arvoxJRCu5ZzL3SSB5Y_qwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
www.nomadomia.com
2026-09-29 16:03:05
(4 days ago)
Hack attack .git
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-29 14:26:09
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from SE.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from SE.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/index | UA: moving-to-bins/1.0 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-29 12:02:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:6::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:02:12.418055 2026] [security2:error] [pid 29668:tid 29668] [client 2a02:6ea0:1508:6::d001:49252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mtshastaconcerts.com"] [uri "/.git/index"] [unique_id "aruoxC8FCQZXS_ystSpG6AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-09-29 08:56:48
(4 days ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-29 08:02:48
(4 days ago)
CMS/framework probe: 2a02:6ea0:1508:6::d001 - - [29/Sep/2026:10:02:48 +0200] "GET /.git/index HTTP/2 ...
show more
CMS/framework probe: 2a02:6ea0:1508:6::d001 - - [29/Sep/2026:10:02:48 +0200] "GET /.git/index HTTP/2.0" 444 0 "-" "moving-to-bins/1.0" asn=212238 org="Datacamp Limited" country=SE
...
show less
Web App Attack
๐ฉ๐ช
4server
2026-09-29 07:27:34
(4 days ago)
[TueSep2909:27:30.0761652026][security2:error][pid1953068:tid1953189][client2a02:6ea0:1508:6::d001:0 ...
show more
[TueSep2909:27:30.0761652026][security2:error][pid1953068:tid1953189][client2a02:6ea0:1508:6::d001:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"maxay.ch\"][uri\"/.git/index\"][unique_id\"artoYhzo2psx5hEK70viuAAAAg0\"]
show less
Port Scan
Brute-Force
Web App Attack