๐บ๐ธ
TPI-Abuse
2026-07-20 06:23:06
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 02:22:59.440165 2026] [security2:error] [pid 15557:tid 15557] [client 157.52.92.61:29164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blessedhavenfarm.com"] [uri "/.git/HEAD"] [unique_id "al2-w1POQVcp8cAtYu2BYAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 00:06:53
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 20:06:48.268703 2026] [security2:error] [pid 523:tid 523] [client 157.52.92.61:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aslanhan.com"] [uri "/.git/config"] [unique_id "al1mmAaOx5qdBePfoP4FxAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-07-19 13:13:56
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-19 08:09:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 04:09:21.820564 2026] [security2:error] [pid 26202:tid 26202] [client 157.52.92.61:26060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lonestaredgeworks.com"] [uri "/.git/HEAD"] [unique_id "alyGMVthkVOtoNb4L6xnEwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-07-19 06:48:57
(1 day ago)
dot file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 05:17:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 01:17:17.460413 2026] [security2:error] [pid 22203:tid 22203] [client 157.52.92.61:62964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.36hoursonly.com"] [uri "/.git/config"] [unique_id "alxd3Xppn9RABwxENrJtjwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 04:54:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 00:53:55.849724 2026] [security2:error] [pid 14239:tid 14239] [client 157.52.92.61:52614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.haroturkiye.com"] [uri "/.git/config"] [unique_id "alxYYyCSXe1yEs2CtrO5WgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-19 03:08:14
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.61 (SG/Singapore/-): 1 in t ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.61 (SG/Singapore/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-19 02:22:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 22:22:42.405901 2026] [security2:error] [pid 10589:tid 10589] [client 157.52.92.61:10090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.axiomemail.net"] [uri "/.git/config"] [unique_id "alw08hhlgKD4xB9Ps03adQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 00:59:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 20:59:47.344493 2026] [security2:error] [pid 1521762:tid 1521762] [client 157.52.92.61:54358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.momfoo.com"] [uri "/.git/config"] [unique_id "alwhg4I_GHD3POUNXtpMoAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-19 00:39:00
(1 day ago)
cloudlinux2 fail2ban: 2026-07-19 02:34:16,245 fail2ban.filter [1598]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-19 02:34:16,245 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 157.52.92.20 - 2026-07-19 02:34:16cloudlinux2 fail2ban: 2026-07-19 02:34:16,255 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 157.52.92.20 - 2026-07-19 02:34:16cloudlinux2 fail2ban: 2026-07-19 02:34:38,004 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 193.36.225.95 - 2026-07-19 02:34:37cloudlinux2 fail2ban: 2026-07-19 02:35:33,377 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 188.241.126.43 - 2026-07-19 02:35:33cloudlinux2 fail2ban: 2026-07-19 02:35:38,681 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 172.98.32.15 - 2026-07-19 02:35:38cloudlinux2 fail2ban: 2026-07-19 02:36:00,634 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 157.52.92.61 - 2026-07-19 02:36:00cloudlinux2 fail2ban: 2026-07-19 02:36:00,624 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 157.52.92.61 - 2026-07-19 02:36:00clo
show less
Web App Attack
๐ซ๐ท
masterguru
2026-07-19 00:15:51
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.61 (SG/Singapore/-): 2 in t ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 157.52.92.61 (SG/Singapore/-): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-18 21:08:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 17:08:46.000543 2026] [security2:error] [pid 13257:tid 13275] [client 157.52.92.61:41756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "birdhousefarms.com"] [uri "/.git/config"] [unique_id "alvrXUHynG-JJ9Uv7UfikQAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 10:17:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 06:17:38.622339 2026] [security2:error] [pid 4384:tid 4384] [client 157.52.92.61:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barryherbach.com"] [uri "/.git/HEAD"] [unique_id "altSwoPXFHO31AAcN-VGjAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jkhorvath.com
2026-07-17 13:00:48
(3 days ago)
Request for URL /.git/HEAD
Phishing
Brute-Force
Web App Attack