๐ช๐ธ
Gem
2026-07-17 22:17:42
(3 days ago)
Unauthorized web scan.
Web App Attack
๐จ๐ญ
4server
2026-07-15 13:54:55
(6 days ago)
[WedJul1515:54:52.6141152026][security2:error][pid3674411:tid3674670][client157.52.122.21:0]ModSecur ...
show more
[WedJul1515:54:52.6141152026][security2:error][pid3674411:tid3674670][client157.52.122.21:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"vocenellanima.ch\"][uri\"/.git/HEAD\"][unique_id\"aleRLAZGVxWERHHHMrgp7QAAAUI\"]
show less
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-15 10:33:57
(6 days ago)
cloudlinux2 fail2ban: 2026-07-15 12:28:56,944 fail2ban.filter [1812]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-15 12:28:56,944 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 45.132.227.227 - 2026-07-15 12:28:56cloudlinux2 fail2ban: 2026-07-15 12:29:40,615 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 172.98.32.37 - 2026-07-15 12:29:40cloudlinux2 fail2ban: 2026-07-15 12:29:55,911 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 45.132.227.19 - 2026-07-15 12:29:55cloudlinux2 fail2ban: 2026-07-15 12:30:23,852 fail2ban.filter [1812]: INFO [plesk-modsecurity] Found 157.52.122.21 - 2026-07-15 12:30:23cloudlinux2 fail2ban: 2026-07-15 12:30:23,124 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 209.87.169.45 - 2026-07-15 12:30:22cloudlinux2 fail2ban: 2026-07-15 12:30:23,863 fail2ban.filter [1812]: INFO [plesk-modsecurity] Found 157.52.122.21 - 2026-07-15 12:30:23cloudlinux2 fail2ban: 2026-07-15 12:30:41,887 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 193.56.116.41 - 2026-07-15 12:30:41cloud
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-15 07:55:33
(6 days ago)
[Wed Jul 15 17:55:33.124863 2026] [security2:error] [pid 344485] [client 157.52.122.21:64022] [clien ...
show more
[Wed Jul 15 17:55:33.124863 2026] [security2:error] [pid 344485] [client 157.52.122.21:64022] [client 157.52.122.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "rjryanpartners.com.au"] [uri "/.git/config"] [unique_id "alc89XoYOQE0-pRHvSrFXQAAABg"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 21:50:36
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.122.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.122.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 17:50:30.805159 2026] [security2:error] [pid 22981:tid 22981] [client 157.52.122.21:63904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.keysenterprise.net"] [uri "/.git/config"] [unique_id "alavJv6O9gHQ0RtzWUsPsQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-07-14 16:56:01
(1 week ago)
GET /.git/HEAD HTTP/1.1
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 05:37:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 157.52.122.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.122.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 01:37:51.028471 2026] [security2:error] [pid 6773:tid 6773] [client 157.52.122.21:3678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aquascapes.net"] [uri "/.git/HEAD"] [unique_id "alXLL5gxAxKKLPe3tu3WFgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 00:04:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 157.52.122.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.122.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 20:04:53.340532 2026] [security2:error] [pid 9535:tid 9535] [client 157.52.122.21:27316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rwabutazafoundation.org"] [uri "/.git/config"] [unique_id "alV9JUtukefoMnmSE-zK1wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-07-13 20:35:58
(1 week ago)
dot file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 20:33:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 157.52.122.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.122.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 16:33:46.106639 2026] [security2:error] [pid 17190:tid 17190] [client 157.52.122.21:20784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.travelingguitarfoundation.org"] [uri "/.git/HEAD"] [unique_id "alVLqnW7rY03O8ysp0wUUgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CBJ
2026-07-13 20:18:35
(1 week ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 18:44:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 157.52.122.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.122.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 14:44:50.079444 2026] [security2:error] [pid 26150:tid 26150] [client 157.52.122.21:54400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.drrw.net"] [uri "/.git/HEAD"] [unique_id "alUyIv8-3LQxEc4hAmgXvgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-07-13 13:55:07
(1 week ago)
Accessed trap at '/.git/HEAD'
Web App Attack
๐ต๐ฑ
sefinek.net
2026-07-13 03:40:33
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from SE.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from SE.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/HEAD | UA: git/2.39.2 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ช
voormedia
2026-07-13 02:28:40
(1 week ago)
Accessed trap at '/.git/config'
Web App Attack