๐ณ๐ฑ
Alt255
2026-09-16 00:09:26
(6 hours ago)
[ti-29al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-29al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:c207:2313:8026::1 - - [16/Sep/2026:02:09:12 +0200] "GET /.git/config HTTP/1.1" 301 554 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
auridh
2026-09-15 22:37:21
(7 hours ago)
WAF block: crowdsecurity/vpatch-git-config from 2a02:c207:2313:8026::1 ([REDACTED]) (2 alerts)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 16:59:43
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:59:40.346329 2026] [security2:error] [pid 19592:tid 19592] [client 2a02:c207:2313:8026::1:34528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.globalpackets.net"] [uri "/.git/config"] [unique_id "aql5fKyS3yb-2OaA8-877AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 14:26:44
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:26:41.446793 2026] [security2:error] [pid 7979:tid 7979] [client 2a02:c207:2313:8026::1:53932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "battlestem.com"] [uri "/.git/index"] [unique_id "aqlVodmzEqnvdSuTIaLNNQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 14:07:53
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:07:48.135041 2026] [security2:error] [pid 7331:tid 7388] [client 2a02:c207:2313:8026::1:44206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.worldecom.org"] [uri "/.git/config"] [unique_id "aqlRNAa0wfHdwhNz9YMdYwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 13:43:26
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:43:18.951406 2026] [security2:error] [pid 4700:tid 4824] [client 2a02:c207:2313:8026::1:41604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.threeoakscenter.org"] [uri "/.git/config"] [unique_id "aqlLdtygsSFLjLQJjMJMaQAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-15 13:19:40
(17 hours ago)
[TueSep1515:19:37.6078972026][security2:error][pid3310373:tid3310426][client2a02:c207:2313:8026::1:0 ...
show more
[TueSep1515:19:37.6078972026][security2:error][pid3310373:tid3310426][client2a02:c207:2313:8026::1:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autodiscover.safeoncloud.ch\"][uri\"/.git/config\"][unique_id\"aqlF6fodv-7WOomSYOZNkAAAAUo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 13:01:03
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:00:55.218589 2026] [security2:error] [pid 16019:tid 16019] [client 2a02:c207:2313:8026::1:58300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.pnwdso.org"] [uri "/.git/config"] [unique_id "aqlBh5uuDOmvQuj4aOqBbgAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 11:46:42
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:46:36.161425 2026] [security2:error] [pid 25099:tid 25123] [client 2a02:c207:2313:8026::1:55890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ethicmark.org"] [uri "/.git/config"] [unique_id "aqkwHGpyrwc7LQ2M3_gE-AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 11:26:54
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:26:47.757215 2026] [security2:error] [pid 32595:tid 32595] [client 2a02:c207:2313:8026::1:42588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.calvarycavaliers.org"] [uri "/.git/config"] [unique_id "aqkrd6BiqqUvd84fzXvDSgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 11:11:38
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:11:32.349240 2026] [security2:error] [pid 4209:tid 4209] [client 2a02:c207:2313:8026::1:55376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ultratecnologia.activethinkers.net"] [uri "/wp-config.php.swp"] [unique_id "aqkn5CxHOVoxysMrlBD9ogAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-15 10:28:26
(20 hours ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-15 10:28 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-15 08:55:29
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:55:23.084174 2026] [security2:error] [pid 29414:tid 29414] [client 2a02:c207:2313:8026::1:49982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.zavijava.net"] [uri "/.git/index"] [unique_id "aqkH-8S5b0ayYdh9Wj7n7AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 08:11:36
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:11:27.927333 2026] [security2:error] [pid 19500:tid 19500] [client 2a02:c207:2313:8026::1:37518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.remote911.net"] [uri "/.env.dev"] [unique_id "aqj9r9k1DPkxcnKpx3eRGwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 07:45:24
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2313:8026::1 (vmi3138026.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:45:17.651806 2026] [security2:error] [pid 2924:tid 2924] [client 2a02:c207:2313:8026::1:50832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nwuoregon.org"] [uri "/.env.local"] [unique_id "aqj3jRLJMRkLAGqZgXyhtQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack