πΊπΈ
TPI-Abuse
2026-08-03 07:12:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 03:12:47.551118 2026] [security2:error] [pid 440343:tid 440343] [client 2a04:4e40:4400:0:b8d:a54b:488f:75ed:7106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.neonmotel.com"] [uri "/.git/HEAD"] [unique_id "anA_bypt4CJr23Nxn130qQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-03 05:19:50
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 01:19:44.624308 2026] [security2:error] [pid 1358413:tid 1358413] [client 2a04:4e40:4400:0:b8d:a54b:488f:75ed:25980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.evelowerealtor.com"] [uri "/.git/config"] [unique_id "anAk8NvDgV7wz2Q6i3XIjgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
SX Communications
2026-08-03 03:58:26
(2 months ago)
Blocked abusive HTTP application-layer DoS / botnet traffic from 2a04:4e40:4400:0:b8d:a54b:488f:75ed ...
show more
Blocked abusive HTTP application-layer DoS / botnet traffic from 2a04:4e40:4400:0:b8d:a54b:488f:75ed: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
π§πͺ
cmbplf
2026-08-03 02:37:12
(2 months ago)
162 requests with url.path *.git/*
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-03 01:52:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 21:52:14.981372 2026] [security2:error] [pid 2782842:tid 2782842] [client 2a04:4e40:4400:0:b8d:a54b:488f:75ed:63060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.halotoys.com"] [uri "/.git/HEAD"] [unique_id "am_0TqL4Za8a8nvyIKcEvQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-03 01:20:38
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 21:20:34.336177 2026] [security2:error] [pid 1652504:tid 1652504] [client 2a04:4e40:4400:0:b8d:a54b:488f:75ed:14834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.3rdid7thinf.org"] [uri "/.git/HEAD"] [unique_id "am_s4uG0RkYOGB04Nsn8dAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-03 00:48:23
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 20:48:18.972947 2026] [security2:error] [pid 3080431:tid 3080431] [client 2a04:4e40:4400:0:b8d:a54b:488f:75ed:20198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vaxd.org"] [uri "/.git/config"] [unique_id "am_lUuG9axBilIW9eJURXwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-03 00:29:48
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 20:29:41.975168 2026] [security2:error] [pid 320204:tid 320204] [client 2a04:4e40:4400:0:b8d:a54b:488f:75ed:58350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.flyc2c.com"] [uri "/.git/HEAD"] [unique_id "am_g9dUGCNkSXmAxrEx72wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-02 23:36:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 19:36:08.182702 2026] [security2:error] [pid 26732:tid 26732] [client 2a04:4e40:4400:0:b8d:a54b:488f:75ed:38590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dimensional-solutions.com"] [uri "/.git/HEAD"] [unique_id "am_UaIZYie3_HZZJCeOeaAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-08-02 23:05:46
(2 months ago)
[MonAug0301:05:44.3045252026][security2:error][pid3413762:tid3413806][client2a04:4e40:4400:0:b8d:a54 ...
show more
[MonAug0301:05:44.3045252026][security2:error][pid3413762:tid3413806][client2a04:4e40:4400:0:b8d:a54b:488f:75ed:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"gpwealth.ch\"][uri\"/.git/config\"][unique_id\"am_NSBba2KgMx3ZM_fWcHwAAAEQ\"]
show less
Port Scan
Brute-Force
Web App Attack
π«π·
Baking333
2026-07-15 16:23:45
(2 months ago)
[redacted] 2a04:4e40:4400:0:b8d:a54b:488f:75ed - - [15/Jul/2026:17:23:43 +0100] "GET /.git/config HT ...
show more
[redacted] 2a04:4e40:4400:0:b8d:a54b:488f:75ed - - [15/Jul/2026:17:23:43 +0100] "GET /.git/config HTTP/1.1" 302 6763 0/254075 "-" "git/2.39.2" [redacted] 2a04:4e40:4400:0:b8d:a54b:488f:75ed - - [15/Jul/2026:17:23:43 +0100] "GET /.git/HEAD HTTP/1.1" 302 6763 0/295921 "-" "git/2.39.2"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-15 13:30:36
(2 months ago)
Honeypot triggered: attacker probed /.git/config (1 times)
Web App Attack
Hacking
π¦πΊ
2000cn.com.au
2026-07-15 07:42:34
(2 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π©πͺ
on-com
2026-07-15 01:30:09
(2 months ago)
URL scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-14 02:59:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:4400:0:b8d:a54b:488f:75ed (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 22:58:59.957185 2026] [security2:error] [pid 9448:tid 9448] [client 2a04:4e40:4400:0:b8d:a54b:488f:75ed:2890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.zabyte.net"] [uri "/.git/HEAD"] [unique_id "alWl85BkmPg_d6V2Bxf8UwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack