🇺🇸
TPI-Abuse
2026-09-15 09:42:57
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:42:51.386777 2026] [security2:error] [pid 3912:tid 3912] [client 84.32.244.80:49190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailinghonu.com"] [uri "/.git/info/refs"] [unique_id "aqkTG2w14Oec19bS4Eu2AwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 14:27:51
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 10:27:46.889588 2026] [security2:error] [pid 19814:tid 19866] [client 84.32.244.80:40416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.barstow-station.com"] [uri "/.git/info/refs"] [unique_id "aqgEYjPlsVvOJ19pnTZY5QAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
regishoussin
2026-09-14 13:43:58
(1 day ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-14 13:43 UTC.
show less
Bad Web Bot
Web App Attack
🇧🇪
boxed-it
2026-09-14 11:52:39
(1 day ago)
GET /.git/info/refs?service=git-upload-pack (Tarpitted for 1d15h8m29s, wasted 8.06MB)
Web App Attack
🇺🇸
mnsf
2026-09-14 10:05:05
(1 day ago)
Abuse Detected (29)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 06:48:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:48:50.961644 2026] [security2:error] [pid 26116:tid 26116] [client 84.32.244.80:40846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "labelrecord.com"] [uri "/.git/info/refs"] [unique_id "aqeY0jq0xD5gh30V52DsIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 04:59:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 00:59:10.514272 2026] [security2:error] [pid 20203:tid 20203] [client 84.32.244.80:56382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.zodiacgate.com"] [uri "/.git/info/refs"] [unique_id "aqd_HuzUilqiCVEG_mzUTAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 21:36:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 17:36:22.994759 2026] [security2:error] [pid 11223:tid 11223] [client 84.32.244.80:35414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imagesbyaubrey.com"] [uri "/.git/info/refs"] [unique_id "aqcXVjoOGmIbZeLovBwrYQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 11:15:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 07:14:57.934016 2026] [security2:error] [pid 14037:tid 14037] [client 84.32.244.80:39732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thumbmotorsales.com"] [uri "/.git/info/refs"] [unique_id "aqaFsenUokPgMP3jr4_GMwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 15:01:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 11:01:41.918563 2026] [security2:error] [pid 31074:tid 31074] [client 84.32.244.80:55260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.holtzheimer.net"] [uri "/.git/info/refs"] [unique_id "aqVpVYXYbZnpc78ZIAj78wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
k3rn3l109
2026-09-12 14:34:49
(2 days ago)
Sentinel honeypot: cf-waf-auto hit on sentinelmdm.com UA=git/2.43.0
Hacking
🇺🇸
mnsf
2026-09-11 23:05:13
(3 days ago)
Abuse Detected (19)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 23:42:40
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 19:42:35.601485 2026] [security2:error] [pid 7367:tid 7367] [client 84.32.244.80:58560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "omnitractors.com"] [uri "/.git/info/refs"] [unique_id "aqNAaw3T30SNOntLFLCtBwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 20:09:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 16:09:49.594044 2026] [security2:error] [pid 7627:tid 7627] [client 84.32.244.80:58302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.syndetec.com"] [uri "/.git/info/refs"] [unique_id "aqMOjY8RWccyIZnpNSHH6QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 12:22:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.80 (ip-84-32-244-80.001.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 08:22:45.099990 2026] [security2:error] [pid 29731:tid 29807] [client 84.32.244.80:54828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koalacogs.com"] [uri "/.git/info/refs"] [unique_id "aqKhFbNUS8hZ9sC9u21tPgAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack