๐ฎ๐น
CoreTech srl
2026-07-22 16:11:04
(38 minutes ago)
cloudlinux2 fail2ban: 2026-07-22 18:04:56,711 fail2ban.filter [1589]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-22 18:04:56,711 fail2ban.filter [1589]: INFO [plesk-wordpress] Found 45.8.19.188 - 2026-07-22 18:04:56cloudlinux2 fail2ban: 2026-07-22 18:04:57,343 fail2ban.filter [1589]: INFO [plesk-wordpress] Found 45.8.19.161 - 2026-07-22 18:04:57cloudlinux2 fail2ban: 2026-07-22 18:05:09,515 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 157.52.92.29 - 2026-07-22 18:05:09cloudlinux2 fail2ban: 2026-07-22 18:05:08,372 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 157.52.92.29 - 2026-07-22 18:05:08cloudlinux2 fail2ban: 2026-07-22 18:05:09,833 fail2ban.filter [1589]: INFO [recidive] Found 157.52.92.29 - 2026-07-22 18:05:09cloudlinux2 fail2ban: 2026-07-22 18:05:09,127 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 157.52.92.29 - 2026-07-22 18:05:09cloudlinux2 fail2ban: 2026-07-22 18:05:09,827 fail2ban.actions [1589]: NOTICE [plesk-modsecurity] Ban 157.52.92.29cloudlinux2 fail2ban: 2026-07-22 18:05:08
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 10:50:43
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 06:50:40.981507 2026] [security2:error] [pid 734247:tid 734247] [client 157.52.92.29:39634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tradersworldmarket.com"] [uri "/.git/HEAD"] [unique_id "amCggIXDmRMSlQ79Gao9JAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 00:04:18
(16 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 22:53:48
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 18:53:45.632222 2026] [security2:error] [pid 16492:tid 16492] [client 157.52.92.29:53380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "troyhilldental.com"] [uri "/.git/HEAD"] [unique_id "al_4eULkYt8mlKRDT95mBQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-21 20:28:52
(20 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-07-21 18:39:02
(22 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.29 (SG/Singapore/-): 1 in t ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.29 (SG/Singapore/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ฉ๐ช
big-cloud.nl
2026-07-21 12:31:42
(1 day ago)
Try to access /.git/HEAD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:24:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:24:09.541896 2026] [security2:error] [pid 3779360:tid 3779380] [client 157.52.92.29:33442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tobiume-shounika.kylight.com"] [uri "/.git/HEAD"] [unique_id "al9k6VRkwZdm2K2dpfy-KQAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 11:56:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:56:21.988363 2026] [security2:error] [pid 7611:tid 7664] [client 157.52.92.29:23428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.catch-22productions.com"] [uri "/.git/HEAD"] [unique_id "al9eZUvhcc9lYkoRq-vt5AAAAc8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 10:46:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 06:46:29.850256 2026] [security2:error] [pid 30340:tid 30340] [client 157.52.92.29:48082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.angove.biz"] [uri "/.git/HEAD"] [unique_id "al9OBbZx7M2c964ZfQPcJwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 09:45:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 05:45:18.180078 2026] [security2:error] [pid 230041:tid 230041] [client 157.52.92.29:51220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lucitania.com"] [uri "/.git/HEAD"] [unique_id "al8_rnp8jaCkj8UdVpQCGAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Cyber Crusader
2026-07-21 05:29:14
(1 day ago)
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-21 00:37:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:37:38.194935 2026] [security2:error] [pid 12577:tid 12577] [client 157.52.92.29:39536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hjaltihjalmarsson.com"] [uri "/.git/HEAD"] [unique_id "al6_Uo1hNJXhfWsGvqrjogAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:44:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:44:10.146468 2026] [security2:error] [pid 16384:tid 16384] [client 157.52.92.29:5190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bwmurphy.com"] [uri "/.git/HEAD"] [unique_id "al6yyoHkjWrVbigyFpopQwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:18:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:18:11.825406 2026] [security2:error] [pid 24623:tid 24623] [client 157.52.92.29:61284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.watongacommunitycats.org"] [uri "/.git/HEAD"] [unique_id "al6ssze3Li8y3WpEYJJZ4AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack