🇷🇴
clauss
2026-09-14 04:29:49
(5 hours ago)
84.32.244.109 - - [14/Sep/2026:07:29:47 +0300] "GET /.git/info/refs?service=git-upload-pack HTTP/2.0 ...
show more
84.32.244.109 - - [14/Sep/2026:07:29:47 +0300] "GET /.git/info/refs?service=git-upload-pack HTTP/2.0" 301 0 "-" "git/2.43.0"
84.32.244.109 - - [14/Sep/2026:07:29:48 +0300] "GET /.git/info/refs?service=git-upload-pack HTTP/2.0" 404 22448 "-" "git/2.43.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 03:43:25
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 23:43:17.686941 2026] [security2:error] [pid 7654:tid 7654] [client 84.32.244.109:36012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelsupersonic.com"] [uri "/.git/info/refs"] [unique_id "aqdtVUqmH3ESgOyAXIvefAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 14:57:42
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:57:36.125978 2026] [security2:error] [pid 4665:tid 4665] [client 84.32.244.109:41452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtcdesigns.com"] [uri "/.git/info/refs"] [unique_id "aqa54Kd3a3zbb1QiYRPasgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
René Hickersberger
2026-09-12 19:46:28
(1 day ago)
malicious bot detected: violations="hit-honeypot"; user_agent="git/2.43.0"
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 18:29:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 14:29:44.197159 2026] [security2:error] [pid 15445:tid 15445] [client 84.32.244.109:53510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.littlehorndesign.com"] [uri "/.git/info/refs"] [unique_id "aqWaGFS3flhLk7zZxaIa_QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 01:10:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 21:10:22.570947 2026] [security2:error] [pid 12430:tid 12430] [client 84.32.244.109:43140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.20dekopas.com"] [uri "/.git/info/refs"] [unique_id "aqSmflwj5DnfY3j7X6MSPAAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-11 21:03:36
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/info/refs | 2026-09-11 21:03 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 20:47:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 16:47:28.291407 2026] [security2:error] [pid 7757:tid 7757] [client 84.32.244.109:37880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.konzel.com"] [uri "/.git/info/refs"] [unique_id "aqRo4NvNsKHSxDlt-MVrFgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 13:37:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 09:37:29.299645 2026] [security2:error] [pid 25725:tid 25725] [client 84.32.244.109:56714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toomuchcaffeine.net"] [uri "/.git/info/refs"] [unique_id "aqQEGZRCS6nZtla-XQJjKgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 10:17:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:17:01.784414 2026] [security2:error] [pid 22081:tid 22081] [client 84.32.244.109:48808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.footshufflerz.com"] [uri "/.git/info/refs"] [unique_id "aqPVHcxRGi3K_tXZ2_2MrwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 07:22:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:22:45.258128 2026] [security2:error] [pid 1344:tid 1344] [client 84.32.244.109:57812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doreenkimura.com"] [uri "/.git/info/refs"] [unique_id "aqOsRawGi7w3BU6T17-T2gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 07:02:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:02:10.591251 2026] [security2:error] [pid 22663:tid 22663] [client 84.32.244.109:47990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mms-boss.net"] [uri "/.git/info/refs"] [unique_id "aqOncmR98xmbmjB5iPsa7QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 02:30:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:29:55.233413 2026] [security2:error] [pid 23014:tid 23014] [client 84.32.244.109:48622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.debbiegarner.com"] [uri "/.git/info/refs"] [unique_id "aqNno3EoNsenx9JF53Cb8wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 16:28:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.109 (ip-84-32-244-109.010.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 12:28:15.524726 2026] [security2:error] [pid 21717:tid 21717] [client 84.32.244.109:43216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.net-gal.com"] [uri "/.git/info/refs"] [unique_id "aqLan0GPqdZXc1xZKO5oMgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-10 07:31:22
(4 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack