|
๐บ๐ธ
2400:cb00:1293:1000:fbef:b408:8f79:f86e
|
|
(mod_security) mod_security (id:210492) triggered by 2400:cb00:1293:1000:fbef:b408:8f79:f86e (Unknow ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:1293:1000:fbef:b408:8f79:f86e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:27.611994 2026] [security2:error] [pid 8951:tid 8951] [client 2400:cb00:1293:1000:fbef:b408:8f79:f86e:14022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.abbeygardensllandudno.com"] [uri "/.git/config"] [unique_id "aoLpjxB3Dw97zgBG8MYadwAAACg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐ท๐บ
79.111.41.132
|
|
(mod_security) mod_security (id:210730) triggered by 79.111.41.132 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 79.111.41.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:26.498212 2026] [security2:error] [pid 18203:tid 18203] [client 79.111.41.132:56056] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||benjaminshaw.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "benjaminshaw.com"] [uri "/baggywrinkle/images/WS_FTP.LOG"] [unique_id "aoLpjnS5F9-2IS7zwshF7QAAABE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
104.22.101.82
|
|
(mod_security) mod_security (id:210492) triggered by 104.22.101.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:27.219200 2026] [security2:error] [pid 1759:tid 1839] [client 104.22.101.82:11146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.oplconnect.com"] [uri "/.git/config"] [unique_id "aoLpj3-CxSq_jrfv2xLP5wAAAY0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐ฎ๐ณ
103.220.30.153
|
|
(mod_security) mod_security (id:240335) triggered by 103.220.30.153 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.220.30.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:25.107146 2026] [security2:error] [pid 32672:tid 32672] [client 103.220.30.153:53370] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.220.30.153 (+1 hits since last alert)|nccb.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nccb.org"] [uri "/xmlrpc.php"] [unique_id "aoLpjZBvKPN8yFqnwf_XMgAAAA0"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐น๐ท
159.146.9.66
|
|
(mod_security) mod_security (id:210730) triggered by 159.146.9.66 (66.9.146.159.srv.turk.net): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 159.146.9.66 (66.9.146.159.srv.turk.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:23.603929 2026] [security2:error] [pid 25159:tid 25159] [client 159.146.9.66:50367] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||benjaminshaw.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "benjaminshaw.com"] [uri "/baggywrinkle/images/WS_FTP.LOG"] [unique_id "aoLpiyZhg8ETL5oa6UkrUwAAAAQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐ฆ๐ช
2.50.20.130
|
|
(mod_security) mod_security (id:240335) triggered by 2.50.20.130 (bba-2-50-20-130.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.20.130 (bba-2-50-20-130.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:22.123884 2026] [security2:error] [pid 17214:tid 17227] [client 2.50.20.130:55843] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.20.130 (+1 hits since last alert)|utahhoaservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "utahhoaservices.com"] [uri "/xmlrpc.php"] [unique_id "aoLpivxkckhCx5gW--10hQAAAQs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐ฌ๐ง
209.50.180.87
|
|
(mod_security) mod_security (id:225170) triggered by 209.50.180.87 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 209.50.180.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:21.439083 2026] [security2:error] [pid 7953:tid 7953] [client 209.50.180.87:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cloudex.click|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cloudex.click"] [uri "/wp-json/wp/v2/users"] [unique_id "aoLpiV5JGaeuzZdYcJpvCQAAAAU"], referer: https://t.co/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
172.71.223.14
|
|
(mod_security) mod_security (id:210492) triggered by 172.71.223.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.223.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:22.386289 2026] [security2:error] [pid 23407:tid 23407] [client 172.71.223.14:12402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vertirama.com"] [uri "/.git/config"] [unique_id "aoLpit33E-pObzbhfkhkagAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
172.71.223.13
|
|
(mod_security) mod_security (id:210492) triggered by 172.71.223.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.223.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:22.386305 2026] [security2:error] [pid 32451:tid 32451] [client 172.71.223.13:12332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vertirama.com"] [uri "/.git/HEAD"] [unique_id "aoLpijcvlGHykXpUa_J9mwAAAAs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
172.71.194.93
|
|
(mod_security) mod_security (id:210492) triggered by 172.71.194.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.194.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:16.233157 2026] [security2:error] [pid 32467:tid 32467] [client 172.71.194.93:11851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.futureproductionsonline.com"] [uri "/.git/config"] [unique_id "aoLphKaMgLozqSisEaxGfgAAAAY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
172.71.194.92
|
|
(mod_security) mod_security (id:210492) triggered by 172.71.194.92 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.194.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:16.234272 2026] [security2:error] [pid 17959:tid 17959] [client 172.71.194.92:12500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.futureproductionsonline.com"] [uri "/.git/HEAD"] [unique_id "aoLphMtyJ9ANe6QOi0Aa-gAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
104.22.101.179
|
|
(mod_security) mod_security (id:210492) triggered by 104.22.101.179 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:14.020995 2026] [security2:error] [pid 6473:tid 6473] [client 104.22.101.179:14332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.austli.com"] [uri "/.git/config"] [unique_id "aoLpghOy6A6d-R8fPvMbqgAAABY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
104.22.101.178
|
|
(mod_security) mod_security (id:210492) triggered by 104.22.101.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.101.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:14.020986 2026] [security2:error] [pid 3347:tid 3347] [client 104.22.101.178:10229] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.austli.com"] [uri "/.git/HEAD"] [unique_id "aoLpgrpwGnEOJQMiqfUTAgAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
104.23.209.43
|
|
(mod_security) mod_security (id:210492) triggered by 104.23.209.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.209.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:09.358384 2026] [security2:error] [pid 17832:tid 17832] [client 104.23.209.43:13442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hygeiamedical.icu"] [uri "/.git/HEAD"] [unique_id "aoLpfaNled49LusBTejnMgAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
172.68.245.139
|
|
(mod_security) mod_security (id:210492) triggered by 172.68.245.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:04.863606 2026] [security2:error] [pid 1683:tid 1738] [client 172.68.245.139:9444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.malia97.com"] [uri "/.git/config"] [unique_id "aoLpeCxDZiwUBNkvmuoA9wAAABQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
104.22.93.76
|
|
(mod_security) mod_security (id:210492) triggered by 104.22.93.76 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.93.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:07.474810 2026] [security2:error] [pid 14413:tid 14413] [client 104.22.93.76:10815] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.newlifecommunitycare.org"] [uri "/.git/HEAD"] [unique_id "aoLpe6Yam_IhATWOlM1KswAAABo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
2400:cb00:1290:1000:7a03:c8cf:38a2:c276
|
|
(mod_security) mod_security (id:210492) triggered by 2400:cb00:1290:1000:7a03:c8cf:38a2:c276 (Unknow ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:1290:1000:7a03:c8cf:38a2:c276 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:05.570076 2026] [security2:error] [pid 6195:tid 6195] [client 2400:cb00:1290:1000:7a03:c8cf:38a2:c276:10265] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oakleighfarm.com"] [uri "/.git/HEAD"] [unique_id "aoLpeSjszGuZ3JK6EsbZegAAACY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
2400:cb00:1025:1000:a560:2e82:c720:b8c9
|
|
(mod_security) mod_security (id:210492) triggered by 2400:cb00:1025:1000:a560:2e82:c720:b8c9 (Unknow ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:1025:1000:a560:2e82:c720:b8c9 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:04.800355 2026] [security2:error] [pid 6194:tid 6194] [client 2400:cb00:1025:1000:a560:2e82:c720:b8c9:9560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.devinfrymire.com"] [uri "/.git/config"] [unique_id "aoLpeMT1xOpFtuCNHcQOXgAAABk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐ฎ๐ณ
202.89.67.138
|
|
(mod_security) mod_security (id:240335) triggered by 202.89.67.138 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.89.67.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:58:50.578453 2026] [security2:error] [pid 32647:tid 32752] [client 202.89.67.138:7912] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.89.67.138 (+1 hits since last alert)|nordicatrio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nordicatrio.com"] [uri "/xmlrpc.php"] [unique_id "aoLpatikLFsc0FA_e-7v9QAAAVQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
172.71.194.36
|
|
(mod_security) mod_security (id:210492) triggered by 172.71.194.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.194.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:00.461644 2026] [security2:error] [pid 7292:tid 7292] [client 172.71.194.36:12067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.c2cdisasterresponse.org"] [uri "/.git/config"] [unique_id "aoLpdNyOu61HI5UK_liX-AAAAB4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐ต๐ฐ
182.184.116.119
|
|
(mod_security) mod_security (id:240335) triggered by 182.184.116.119 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 182.184.116.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:59:01.255337 2026] [security2:error] [pid 8015:tid 8015] [client 182.184.116.119:57539] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 182.184.116.119 (+1 hits since last alert)|thereisaplaceonearth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thereisaplaceonearth.com"] [uri "/xmlrpc.php"] [unique_id "aoLpdQR0lS6_cb5Q4i7dXgAAAAo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
104.22.100.112
|
|
(mod_security) mod_security (id:210492) triggered by 104.22.100.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:58:57.455876 2026] [security2:error] [pid 21369:tid 21369] [client 104.22.100.112:9645] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beercruisers.glassicannex.org"] [uri "/.git/config"] [unique_id "aoLpcfjPaGgRio5xmb9JkgAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐ฒ๐ฆ
105.157.229.116
|
|
(mod_security) mod_security (id:240335) triggered by 105.157.229.116 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 105.157.229.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:58:54.619579 2026] [security2:error] [pid 13294:tid 13294] [client 105.157.229.116:64188] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 105.157.229.116 (+1 hits since last alert)|become-a-medicalsalesrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "become-a-medicalsalesrep.com"] [uri "/xmlrpc.php"] [unique_id "aoLpbgJG7UzbPtlAJ-NT8AAAAAs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐บ๐ธ
104.22.100.23
|
|
(mod_security) mod_security (id:210492) triggered by 104.22.100.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.22.100.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:58:57.445978 2026] [security2:error] [pid 25829:tid 25829] [client 104.22.100.23:11051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beercruisers.glassicannex.org"] [uri "/.git/HEAD"] [unique_id "aoLpcZudg3nTqJte9IOp5wAAABg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
๐ญ๐ฐ
121.127.233.202
|
|
(mod_security) mod_security (id:218420) triggered by 121.127.233.202 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218420) triggered by 121.127.233.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:58:44.956144 2026] [security2:error] [pid 28546:tid 28550] [client 121.127.233.202:51102] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.22:80|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.22"] [uri "/hello.world"] [unique_id "aoLpZH76hw9wzqV1DO1q_gAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|