๐บ๐ธ
TPI-Abuse
2026-07-25 13:49:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 09:49:46.588442 2026] [security2:error] [pid 1381261:tid 1381261] [client 140.248.75.137:60438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beckersystems.com"] [uri "/.git/HEAD"] [unique_id "amS--mSFTWuRp8aSKEMoywAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 13:04:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 09:04:25.271179 2026] [security2:error] [pid 4093340:tid 4093340] [client 140.248.75.137:45902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kayelynn.com"] [uri "/.git/HEAD"] [unique_id "amS0WfWHblWbyGpgbQYfHQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 19:59:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 15:59:23.830720 2026] [security2:error] [pid 3973005:tid 3973005] [client 140.248.75.137:63722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "springmeadowventures.com"] [uri "/.git/HEAD"] [unique_id "amJym8zoQs8ilarwNC1rtgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-22 20:11:28
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-22 19:33:25
(4 days ago)
Try to access /.git/HEAD
Web App Attack
Anonymous
2026-07-22 09:33:26
(4 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
Actors.Bible
2026-07-21 14:05:22
(5 days ago)
Webapp Vulnerability Probing:
GET /.git/HEAD
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-21 11:58:56
(5 days ago)
cloudlinux2 fail2ban: 2026-07-21 13:55:07,763 fail2ban.filter [1927]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-21 13:55:07,763 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 140.248.75.137 - 2026-07-21 13:55:07cloudlinux2 fail2ban: 2026-07-21 13:55:07,043 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 140.248.75.137 - 2026-07-21 13:55:07cloudlinux2 fail2ban: 2026-07-21 13:55:08,672 fail2ban.actions [1927]: NOTICE [plesk-modsecurity] Ban 140.248.75.137cloudlinux2 fail2ban: 2026-07-21 13:55:08,666 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 140.248.75.137 - 2026-07-21 13:55:08cloudlinux2 fail2ban: 2026-07-21 13:55:08,680 fail2ban.filter [1927]: INFO [recidive] Found 140.248.75.137 - 2026-07-21 13:55:08cloudlinux2 fail2ban: 2026-07-21 13:55:20,206 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 91.193.232.177 - 2026-07-21 13:55:19cloudlinux2 fail2ban: 2026-07-21 13:55:20,216 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 45.130.83.131 - 2026-07-21 13:55:20cloudlinux2 fail2ban: 2026
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 22:47:33
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 18:47:27.866226 2026] [security2:error] [pid 8428:tid 8428] [client 140.248.75.137:39616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edwinrphotography.grayhost.net"] [uri "/.git/HEAD"] [unique_id "al6lf4ASZFokRJFIoJ0-MAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-20 21:52:29
(6 days ago)
csagent: score 19.0: 404 noise floor x2, secrets grab x2; 2 domain(s) in 28s
Web App Attack
๐ซ๐ท
masterguru
2026-07-20 18:46:11
(6 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 140.248.75.137 (GB/United Kingdom/-): ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 140.248.75.137 (GB/United Kingdom/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-19 12:48:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 08:48:17.739269 2026] [security2:error] [pid 7020:tid 7020] [client 140.248.75.137:2950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jean-louisdarville.com"] [uri "/.git/HEAD"] [unique_id "alzHke_9wn-zvWNfqODpBwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 00:51:01
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 20:50:57.554065 2026] [security2:error] [pid 1974673:tid 1974673] [client 140.248.75.137:40906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.marinawestyachtclub.com"] [uri "/.git/HEAD"] [unique_id "alrN8fejCVzTg2RgRl3YkAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 06:39:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 02:39:23.625286 2026] [security2:error] [pid 605:tid 644] [client 140.248.75.137:19552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.property-management-companies-chicago.com"] [uri "/.git/config"] [unique_id "alnOGxJ2rqaQ2XPkTupfzwAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 05:40:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 140.248.75.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 01:40:15.528017 2026] [security2:error] [pid 4615:tid 4615] [client 140.248.75.137:48742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.meridianranchdrc.org"] [uri "/.git/config"] [unique_id "alhuvyWTITZ9xC8D4etVSwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack