๐ซ๐ท
mail.avx.gr
2026-07-23 11:28:59
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 140.248.227.89 - - [19/Jul/2026:23:20:27 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 140.248.227.89 - - [19/Jul/2026:23:20:27 +0300] "GET /.git/HEAD HTTP/1.1" 403 6280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 15:59:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 11:59:21.966433 2026] [security2:error] [pid 1643683:tid 1643683] [client 140.248.227.89:47698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clcmillvale.com"] [uri "/.git/HEAD"] [unique_id "amDo2esV6lre0bYN7Y_fNAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-21 09:31:24
(3 days ago)
Try to access /.git/HEAD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 19:08:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 15:08:20.350452 2026] [security2:error] [pid 2672598:tid 2672598] [client 140.248.227.89:2048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web202.dnchosting.com"] [uri "/.git/HEAD"] [unique_id "al5yJHNB4TGSMlf1NxCF2gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 09:29:06
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 05:28:57.008747 2026] [security2:error] [pid 18024:tid 18024] [client 140.248.227.89:32886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dogandponyband.com"] [uri "/.git/config"] [unique_id "al3qWfoPDXO4cViaYEmiZwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 06:02:41
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 02:02:34.805044 2026] [security2:error] [pid 15118:tid 15118] [client 140.248.227.89:28160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hadleymarketing.com"] [uri "/.git/HEAD"] [unique_id "al25-nmo3OANFmcMZrg8fgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-19 20:20:28
(4 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 140.248.227.89 - - [19/Jul/2026:23:20:27 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 140.248.227.89 - - [19/Jul/2026:23:20:27 +0300] "GET /.git/HEAD HTTP/1.1" 403 6280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 17:43:11
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 13:43:04.371266 2026] [security2:error] [pid 4480:tid 4480] [client 140.248.227.89:47802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fuzzyecho.com"] [uri "/.git/HEAD"] [unique_id "al0MqI2DdFN1--VRw5nXQwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 14:23:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 10:23:48.889071 2026] [security2:error] [pid 17805:tid 17805] [client 140.248.227.89:10574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brexitop.com"] [uri "/.git/config"] [unique_id "alzd9Kb7RLnrXHgpNsAWGAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 05:18:07
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 01:18:00.838048 2026] [security2:error] [pid 1181412:tid 1181412] [client 140.248.227.89:10946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globaldentalservices.com"] [uri "/.git/config"] [unique_id "alxeCN5ClFEWtTLJVs931wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 22:15:29
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 18:15:21.024514 2026] [security2:error] [pid 4636:tid 4636] [client 140.248.227.89:9404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hughhart.com"] [uri "/.git/config"] [unique_id "alv6-Wd2n8vWmeYIB7exZAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 06:29:46
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 02:29:39.521529 2026] [security2:error] [pid 2800694:tid 2800694] [client 140.248.227.89:8732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rsrtelecom.net"] [uri "/.git/HEAD"] [unique_id "alsdU104d2PPEfFw0e71hwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 02:21:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 22:21:30.978581 2026] [security2:error] [pid 752102:tid 752102] [client 140.248.227.89:23364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.antech.net"] [uri "/.git/config"] [unique_id "alrjKmmDjgIboDjCKF1Z6gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 19:36:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 15:36:33.437383 2026] [security2:error] [pid 1195556:tid 1195556] [client 140.248.227.89:46980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.samanthasomers.com"] [uri "/.git/HEAD"] [unique_id "alqEQVc1CbId3xAP7pVSvgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 02:23:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.227.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 22:23:21.227530 2026] [security2:error] [pid 9734:tid 9734] [client 140.248.227.89:11170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rjabramsonfoundation.org"] [uri "/.git/config"] [unique_id "alhAmXYwWqPyQh6_xq8LtAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack