๐ซ๐ท
mail.avx.gr
2026-07-23 11:29:31
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: avaxsh.avx.gr:443 157.52.92.64 - - [20/Jul/2026:2 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: avaxsh.avx.gr:443 157.52.92.64 - - [20/Jul/2026:21:55:09 +0300] "GET /.git/HEAD HTTP/1.1" 403 5654 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-22 20:28:29
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 157.52.92.64 (SG/Singapore/-): 1 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 157.52.92.64 (SG/Singapore/-): 1 in the last 3600 secs
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-07-22 12:30:08
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-07-22 04:05:07
(2 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 19:30:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 15:30:03.583666 2026] [security2:error] [pid 11811:tid 11811] [client 157.52.92.64:26252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rockinr.org"] [uri "/.git/HEAD"] [unique_id "al_Iu8QTCYOZFdckB6v1IgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 18:27:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:27:34.153348 2026] [security2:error] [pid 12585:tid 12611] [client 157.52.92.64:38976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.barrywillis.org"] [uri "/.git/HEAD"] [unique_id "al-6FrA3X6bFtLkRkRnXOwAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 10:39:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 06:39:17.771635 2026] [security2:error] [pid 2490820:tid 2490820] [client 157.52.92.64:37734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clockandnightlight.com"] [uri "/.git/HEAD"] [unique_id "al9MVZMAnYnsW000gTtQ4AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 09:39:18
(3 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 09:02:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 05:02:30.511029 2026] [security2:error] [pid 28176:tid 28176] [client 157.52.92.64:21462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smoothiessoupssalads.com"] [uri "/.git/HEAD"] [unique_id "al81pvmbb-3J5z-M57qPxQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Cyber Crusader
2026-07-21 05:12:05
(3 days ago)
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan
Hacking
Brute-Force
๐ซ๐ท
mail.avx.gr
2026-07-20 18:55:10
(4 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: avaxsh.avx.gr:443 157.52.92.64 - - [20/Jul/2026:2 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: avaxsh.avx.gr:443 157.52.92.64 - - [20/Jul/2026:21:55:09 +0300] "GET /.git/HEAD HTTP/1.1" 403 5654 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:52:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:52:48.967436 2026] [security2:error] [pid 2877:tid 2877] [client 157.52.92.64:24266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "framestoria.vittariadesign.com"] [uri "/.git/HEAD"] [unique_id "al5gcIGVaIKBqRu_AEAv9gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:28:01
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:27:55.957104 2026] [security2:error] [pid 22298:tid 22298] [client 157.52.92.64:37094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sabri.es"] [uri "/.git/HEAD"] [unique_id "al5am93ZPtOLfWGmhXWjGAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 11:19:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:19:11.783253 2026] [security2:error] [pid 31756:tid 31756] [client 157.52.92.64:37058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blublk.com"] [uri "/.git/HEAD"] [unique_id "al4ELxBgIbsyigZucPCQLQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 07:17:58
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 03:17:51.147583 2026] [security2:error] [pid 31367:tid 31367] [client 157.52.92.64:52248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aavondalervstorage.com"] [uri "/.git/config"] [unique_id "al3Ln0EHnxtfVxILEUdyMwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack