Anonymous
2026-09-10 10:34:32
(58 minutes ago)
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show more
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-10 10:03:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 06:03:35.907345 2026] [security2:error] [pid 5964:tid 5964] [client 84.32.244.97:45586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.grassnplus.com"] [uri "/.git/info/refs"] [unique_id "aqKAd2sFD67hXoa75r--6AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 22:12:55
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 18:12:51.873562 2026] [security2:error] [pid 24717:tid 24717] [client 84.32.244.97:52280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sigi.biz"] [uri "/.git/info/refs"] [unique_id "aqHZ454pjP7cOH4I0kLZbQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 19:38:58
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 15:38:53.373953 2026] [security2:error] [pid 14603:tid 14629] [client 84.32.244.97:53128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dpiazza.com"] [uri "/.git/info/refs"] [unique_id "aqG1zbvKZi3vY6m7tqbYqQAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 18:37:13
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 14:37:08.975416 2026] [security2:error] [pid 9269:tid 9269] [client 84.32.244.97:45628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lawson-insurance.com"] [uri "/.git/info/refs"] [unique_id "aqGnVHPIo_SL2EFgJi0wcQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 17:11:44
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 13:11:35.703688 2026] [security2:error] [pid 10728:tid 10728] [client 84.32.244.97:33648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davesullivan.net"] [uri "/.git/info/refs"] [unique_id "aqGTR5aavXPsUI06PGxdowAAAGA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:38:00
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:37:54.852719 2026] [security2:error] [pid 15709:tid 15709] [client 84.32.244.97:60072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.helloauto.net"] [uri "/.git/info/refs"] [unique_id "aqFFEhS13WGWE2FxO7oougAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:38:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:38:44.501641 2026] [security2:error] [pid 536299:tid 536419] [client 84.32.244.97:38814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joshuapaulweckesser.com"] [uri "/.git/info/refs"] [unique_id "aqC4pLdqgKcUbA4wGrJQxQAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:25:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:24:56.701703 2026] [security2:error] [pid 6018:tid 6018] [client 84.32.244.97:56566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.delucchi.net"] [uri "/.git/info/refs"] [unique_id "aqCnWBTL5O6tiomctsB31QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-09 00:05:15
(1 day ago)
Abuse Detected (9)
Brute-Force
Web App Attack
Anonymous
2026-09-08 22:38:11
(1 day ago)
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show more
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 20:14:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:14:12.248948 2026] [security2:error] [pid 6457:tid 6457] [client 84.32.244.97:55326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srossi.net"] [uri "/.git/info/refs"] [unique_id "aqBslIZuc5cmutuaYKsarAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:51:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:51:47.110140 2026] [security2:error] [pid 6164:tid 6164] [client 84.32.244.97:59010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.solmedsolicitors.com"] [uri "/.git/info/refs"] [unique_id "aqBnUyLT8xY65l7AAr_CTgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:50:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:50:35.324151 2026] [security2:error] [pid 808:tid 808] [client 84.32.244.97:47726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rhkglobal.com"] [uri "/.git/info/refs"] [unique_id "aqBY-5olDDkCz4vA6BPZewAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:00:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryser ...
show more
(mod_security) mod_security (id:210492) triggered by 84.32.244.97 (ip-84-32-244-97.008.ptr.cherryservers.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:00:02.331448 2026] [security2:error] [pid 17210:tid 17210] [client 84.32.244.97:38232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zavijava.net"] [uri "/.git/info/refs"] [unique_id "aqBNIvjN3fdzBBg8dBW-ZwAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack