๐บ๐ธ
TPI-Abuse
2026-07-27 10:44:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:44:42.980292 2026] [security2:error] [pid 1248012:tid 1248012] [client 2a04:4e40:e000:0:33c:a689:be95:5a4:15670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aceshd.mroxygen.org"] [uri "/.git/HEAD"] [unique_id "amc2mtlbSphZqrvdc5vUuQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-07-27 10:31:42
(1 month ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-27 10:26:05
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-25 15:30:48
(1 month ago)
[SatJul2517:30:45.2257202026][security2:error][pid115447:tid115520][client2a04:4e40:e000:0:33c:a689: ...
show more
[SatJul2517:30:45.2257202026][security2:error][pid115447:tid115520][client2a04:4e40:e000:0:33c:a689:be95:5a4:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autodiscover.admin-services.ch\"][uri\"/.git/HEAD\"][unique_id\"amTWpSGfW2Tpqaw08D-8JgAAAIw\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 13:05:28
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 09:05:23.057058 2026] [security2:error] [pid 2085681:tid 2085681] [client 2a04:4e40:e000:0:33c:a689:be95:5a4:37660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kristencorley.com"] [uri "/.git/HEAD"] [unique_id "amS0k3nZ2oKVwoBkHWOMkgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 00:40:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 20:40:45.602844 2026] [security2:error] [pid 652851:tid 652851] [client 2a04:4e40:e000:0:33c:a689:be95:5a4:17694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.franknash.com"] [uri "/.git/HEAD"] [unique_id "amQGDZDw6wsI7Sy3mQoenQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 04:31:45
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐จ๐ญ
4server
2026-07-20 22:43:39
(1 month ago)
[TueJul2100:43:32.4396582026][security2:error][pid3435682:tid3436142][client2a04:4e40:e000:0:33c:a68 ...
show more
[TueJul2100:43:32.4396582026][security2:error][pid3435682:tid3436142][client2a04:4e40:e000:0:33c:a689:be95:5a4:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webdisk.mondo-it.ch\"][uri\"/.git/HEAD\"][unique_id\"al6klAPQLRQe93s0PlChcgAAAUc\"]
show less
Hacking
Web App Attack
๐บ๐ธ
interbiznw.com
2026-07-20 19:28:28
(1 month ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:28:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:28:15.451461 2026] [security2:error] [pid 6782:tid 6782] [client 2a04:4e40:e000:0:33c:a689:be95:5a4:53352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "otrantocapital.com"] [uri "/.git/HEAD"] [unique_id "al5ar2HTq8T6opx7aMEMVwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-07-20 17:16:47
(1 month ago)
(y3) Failed access -byebye- from 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): (CF_ENABLE)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-19 10:18:32
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 06:18:27.027054 2026] [security2:error] [pid 377:tid 377] [client 2a04:4e40:e000:0:33c:a689:be95:5a4:14752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clevelanddental.org"] [uri "/.git/HEAD"] [unique_id "alykcxYhJvygmUxnDwwkbAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 09:20:21
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 05:20:16.570014 2026] [security2:error] [pid 85009:tid 85028] [client 2a04:4e40:e000:0:33c:a689:be95:5a4:37344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.plasticsurgeondallas.com.aafm.us"] [uri "/.git/HEAD"] [unique_id "alyW0MKLxeL3JAoEXFa7hwAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 00:46:50
(2 months ago)
(mod_security) mod_security (id:949110) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 ...
show more
(mod_security) mod_security (id:949110) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 20:46:46.480374 2026] [security2:error] [pid 1119342:tid 1119342] [client 2a04:4e40:e000:0:33c:a689:be95:5a4:32026] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dcagroupusa.com"] [uri "/.git/config"] [unique_id "alwedtbdzRyENJttJRb4GAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 01:39:38
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:33c:a689:be95:5a4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 21:39:32.150019 2026] [security2:error] [pid 3271:tid 3271] [client 2a04:4e40:e000:0:33c:a689:be95:5a4:32588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americancryonics.org"] [uri "/.git/config"] [unique_id "alg2VJJArC2nHTfKEfiiwgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack