๐บ๐ธ
TPI-Abuse
2026-07-27 15:35:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:35:08.701473 2026] [security2:error] [pid 3640523:tid 3640523] [client 2a04:4e40:e000:0:566:f8d7:adbe:f536:39350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.box.jen-eric.com"] [uri "/.git/HEAD"] [unique_id "amd6rIaQlrDsXGkXPEjpXQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-07-27 10:34:03
(1 month ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
ScamAware
2026-07-27 10:33:45
(1 month ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 4. Unique request paths counted internally: 2. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 11:23:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 07:23:44.147908 2026] [security2:error] [pid 4058048:tid 4058120] [client 2a04:4e40:e000:0:566:f8d7:adbe:f536:11732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "almerirock.com"] [uri "/.git/HEAD"] [unique_id "amXuQKXa7fTlLt3yZIGNXwAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 10:30:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 06:30:24.951302 2026] [security2:error] [pid 18020:tid 18020] [client 2a04:4e40:e000:0:566:f8d7:adbe:f536:49834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.windisfun.com"] [uri "/.git/HEAD"] [unique_id "amSQQDJtIlafit9ibVMdtwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 12:13:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 08:13:31.659770 2026] [security2:error] [pid 786691:tid 786691] [client 2a04:4e40:e000:0:566:f8d7:adbe:f536:15358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forwardti.com"] [uri "/.git/HEAD"] [unique_id "amCz6z6_qS78EHZUIARNMQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-07-22 00:06:15
(1 month ago)
HTTP vulnerability scanning
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-21 23:19:09
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 23:01:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 19:01:46.254065 2026] [security2:error] [pid 514954:tid 514972] [client 2a04:4e40:e000:0:566:f8d7:adbe:f536:37500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.globalpartssolution.com"] [uri "/.git/HEAD"] [unique_id "al_6Wr3vN0hWaW5STW6M-QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-07-20 11:44:33
(1 month ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฎ๐น
zenmorro
2026-07-20 01:20:04
(1 month ago)
Honeypot hit (imperocms:0) โ [honeypot] Tentativo lettura .git/config | GET /.git/config | UA: Mozil ...
show more
Honeypot hit (imperocms:0) โ [honeypot] Tentativo lettura .git/config | GET /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36. Automated report from honeypot infrastructure
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-19 16:31:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 12:31:51.270127 2026] [security2:error] [pid 29344:tid 29344] [client 2a04:4e40:e000:0:566:f8d7:adbe:f536:40534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ssion.com"] [uri "/.git/HEAD"] [unique_id "alz79yEzV2Vj9zc6cZgIlgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
kumiko
2026-07-19 05:14:58
(1 month ago)
[2026-07-19 08:14:57] Probing for dotfiles
"GET /.git/HEAD HTTP/1.1" 301
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 00:07:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 20:07:54.117542 2026] [security2:error] [pid 2976934:tid 2976934] [client 2a04:4e40:e000:0:566:f8d7:adbe:f536:32788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kemblebrothers.com"] [uri "/.git/HEAD"] [unique_id "alwVWqVM2CoIqn5XlUI_KQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 22:09:22
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): ...
show more
(mod_security) mod_security (id:949110) triggered by 2a04:4e40:e000:0:566:f8d7:adbe:f536 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 18:09:17.189709 2026] [security2:error] [pid 985714:tid 985714] [client 2a04:4e40:e000:0:566:f8d7:adbe:f536:59872] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "leseberg.com"] [uri "/.git/config"] [unique_id "alv5jQGqmcP4nlrxb-6f8QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack