🇺🇸
TPI-Abuse
2026-09-21 10:22:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 06:22:28.494169 2026] [security2:error] [pid 27653:tid 27653] [client 84.32.244.112:60098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morrofleece.com"] [uri "/.git/info/refs"] [unique_id "arEFZDpUQRdeAp9qrECzzAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Lea
2026-09-21 06:20:00
(8 hours ago)
Malicious web probe detected on bearstool.com: 84.32.244.112 - - [21/Sep/2026:02:20:00 -0400] "GET / ...
show more
Malicious web probe detected on bearstool.com: 84.32.244.112 - - [21/Sep/2026:02:20:00 -0400] "GET /.git/info/refs?service=git-upload-pack HTTP/2.0" 403 5961 "" "git/2.43.0"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 19:25:37
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:25:29.257047 2026] [security2:error] [pid 13412:tid 13412] [client 84.32.244.112:54326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deafinitely.com"] [uri "/.git/info/refs"] [unique_id "arAzKWBO-2-OYQFrDU2P0AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 23:30:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-19 22:58:01
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-18 19:44:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 15:44:45.743252 2026] [security2:error] [pid 32611:tid 32611] [client 84.32.244.112:38260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bendersite.com"] [uri "/.git/info/refs"] [unique_id "aq2UrVC8CxNDJ9LllD8o5gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-18 15:21:59
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dont-eat-the-pudding.top | URI: /.git/info/refs?service=git-upload-pack | UA: git/2.43.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇫🇷
pm33
2026-09-18 12:51:42
(3 days ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-18 00:21:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 20:21:23.133065 2026] [security2:error] [pid 10564:tid 10564] [client 84.32.244.112:42628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rphenry.com"] [uri "/.git/info/refs"] [unique_id "aqyEA6I9oy9i0IR86bRzrAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-17 03:24:09
(4 days ago)
[Thu Sep 17 13:24:09.458055 2026] [security2:error] [pid 453186] [client 84.32.244.112:57234] [clien ...
show more
[Thu Sep 17 13:24:09.458055 2026] [security2:error] [pid 453186] [client 84.32.244.112:57234] [client 84.32.244.112] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mareeshefford.com"] [uri "/.git/info/refs"] [unique_id "aqtdWUrAqtmuLFTvP6j4ugAAAAo"]
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 09:13:04
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 05:12:58.809626 2026] [security2:error] [pid 6925:tid 6925] [client 84.32.244.112:52298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rebelhollowfarm.com"] [uri "/.git/info/refs"] [unique_id "aqpdmnTmrI5pP2XtF8PdywAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 03:02:12
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:02:07.567768 2026] [security2:error] [pid 29115:tid 29115] [client 84.32.244.112:38436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indianamanpodcast.com"] [uri "/.git/info/refs"] [unique_id "aqoGryjTsZc5bqjV1g207QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 08:16:42
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:16:34.281456 2026] [security2:error] [pid 13747:tid 13833] [client 84.32.244.112:40126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.robertbellamystudio.com"] [uri "/.git/info/refs"] [unique_id "aqj-4tzgxp0TV4HX8mqK9wAAAdY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 06:52:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:52:00.460797 2026] [security2:error] [pid 6958:tid 6958] [client 84.32.244.112:55648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.3dstores.com"] [uri "/.git/info/refs"] [unique_id "aqeZkH0io_BCHxDpIiP5MAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 05:04:53
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherrys ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.112 (ip-84-32-244-112.003.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 01:04:48.386367 2026] [security2:error] [pid 2315:tid 2315] [client 84.32.244.112:53840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ladymfashion.com"] [uri "/.git/info/refs"] [unique_id "aqeAcKm8cIEuL08EcFT0FQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack