๐บ๐ธ
TPI-Abuse
2026-07-21 18:18:09
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:18:03.971106 2026] [security2:error] [pid 6399:tid 6406] [client 157.52.92.28:31822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.viasatsales.com"] [uri "/.git/HEAD"] [unique_id "al-32_2894PQmUySOMIIsgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 13:35:16
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 09:35:09.788884 2026] [security2:error] [pid 16933:tid 16933] [client 157.52.92.28:2218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.bendersite.com"] [uri "/.git/HEAD"] [unique_id "al91jUiN8n-ntsXwwtNQrQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-21 13:14:48
(17 hours ago)
csagent: score 15.4: secrets grab x2; 2 domain(s) in 1m47s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:51:14
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:51:08.449147 2026] [security2:error] [pid 5866:tid 5866] [client 157.52.92.28:7298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tradersworldmarket.com"] [uri "/.git/HEAD"] [unique_id "al9rPMv_GByAMI9jAduyCwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-07-20 23:08:39
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 22:06:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 18:06:48.925328 2026] [security2:error] [pid 24161:tid 24161] [client 157.52.92.28:40028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.register-yacht-spain.com"] [uri "/.git/HEAD"] [unique_id "al6b-DFZDSG2G9ffxy-w8AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 19:01:00
(1 day ago)
PSCSERV WPSCAN 157.52.92.28
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 18:35:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 18:23:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 14:23:54.100503 2026] [security2:error] [pid 1731336:tid 1731336] [client 157.52.92.28:27236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.acpalms.com"] [uri "/.git/HEAD"] [unique_id "al5nul5TYS4PF1p1bVB6dAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-20 17:43:57
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.28 (SG/Singapore/-): 1 in t ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.28 (SG/Singapore/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-20 17:06:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:06:28.653131 2026] [security2:error] [pid 30957:tid 30957] [client 157.52.92.28:53496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sp.cloudex.link"] [uri "/.git/HEAD"] [unique_id "al5VlLfP8vkbGC3GOieppwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 13:03:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 09:03:48.673901 2026] [security2:error] [pid 20236:tid 20236] [client 157.52.92.28:42508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.armrms.com"] [uri "/.git/config"] [unique_id "al4ctE0vbAFvcE4uKCwFHQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 12:05:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 08:05:10.892535 2026] [security2:error] [pid 13336:tid 13336] [client 157.52.92.28:47662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boat-registration-france.com.boatregistrationdelaware.com"] [uri "/.git/config"] [unique_id "al4O9tOK4SLdloFA47Ta1gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-07-20 11:57:07
(1 day ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 06:02:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 02:02:23.376621 2026] [security2:error] [pid 18538:tid 18538] [client 157.52.92.28:19204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lejzerowicz.org"] [uri "/.git/config"] [unique_id "al257-zbk39YEaJkrnZa1gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack