๐บ๐ธ
TPI-Abuse
2026-07-22 10:00:59
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 06:00:52.009590 2026] [security2:error] [pid 687350:tid 687350] [client 157.52.92.73:15256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dennisangellismusic.com"] [uri "/.git/HEAD"] [unique_id "amCU1Gia1MmUavapsbgpgwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-21 19:56:01
(21 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 18:54:11
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:54:06.393550 2026] [security2:error] [pid 13330:tid 13330] [client 157.52.92.73:65058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tracdynamics.com"] [uri "/.git/HEAD"] [unique_id "al_ATi_4ICBw_hV6d8YmowAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 14:52:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 10:52:15.833601 2026] [security2:error] [pid 25508:tid 25508] [client 157.52.92.73:40314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mnalabama.com"] [uri "/.git/HEAD"] [unique_id "al-Hn9BXwENlxtJ3kiVoXAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-21 09:03:02
(1 day ago)
Try to access /.git/HEAD
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-21 08:58:56
(1 day ago)
cloudlinux2 fail2ban: 2026-07-21 10:54:03,578 fail2ban.filter [1927]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-21 10:54:03,578 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 193.36.225.132 - 2026-07-21 10:54:02cloudlinux2 fail2ban: 2026-07-21 10:54:21,830 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 193.19.109.244 - 2026-07-21 10:54:21cloudlinux2 fail2ban: 2026-07-21 10:54:21,035 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 157.52.92.73 - 2026-07-21 10:54:21cloudlinux2 fail2ban: 2026-07-21 10:54:21,969 fail2ban.actions [1927]: NOTICE [plesk-modsecurity] Ban 157.52.92.73cloudlinux2 fail2ban: 2026-07-21 10:54:20,268 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 157.52.92.73 - 2026-07-21 10:54:20cloudlinux2 fail2ban: 2026-07-21 10:54:21,786 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 157.52.92.73 - 2026-07-21 10:54:21cloudlinux2 fail2ban: 2026-07-21 10:54:21,975 fail2ban.filter [1927]: INFO [recidive] Found 157.52.92.73 - 2026-07-21 10:54:21cloudlinux2 fail2ban: 2026-07-21 10
show less
Web App Attack
๐ซ๐ท
UnixPrime
2026-07-21 08:37:24
(1 day ago)
157.52.92.73 - - [21/Jul/2026:10:37:21 +0200] "GET /.git/HEAD HTTP/1.1" 404 14151 "-" "Mozilla/5.0 ( ...
show more
157.52.92.73 - - [21/Jul/2026:10:37:21 +0200] "GET /.git/HEAD HTTP/1.1" 404 14151 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
157.52.92.73 - - [21/Jul/2026:10:37:23 +0200] "GET /.git/HEAD HTTP/1.1" 404 14151 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Epimetheus
2026-07-20 22:20:28
(1 day ago)
Zombie network / Bot scanner detected:
[GET] /.git/HEAD
[GET] /.git/config
[GET] /.git/HEAD
[GET] / ...
show more
Zombie network / Bot scanner detected:
[GET] /.git/HEAD
[GET] /.git/config
[GET] /.git/HEAD
[GET] /.git/HEAD
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
show less
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 21:37:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 17:37:16.059465 2026] [security2:error] [pid 23470:tid 23470] [client 157.52.92.73:50384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pizzadata.com"] [uri "/.git/HEAD"] [unique_id "al6VDJabgJ9rb6qvMulBlQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-07-20 21:29:39
(1 day ago)
Sensitive File Probe
Web App Attack
๐ฆ๐น
centurion
2026-07-20 17:45:40
(1 day ago)
Blocked by UFW on ns03 [443/tcp] Source port: 45628 TTL: 54 Packet length: 60 TOS: 0x00 This report ...
show more
Blocked by UFW on ns03 [443/tcp] Source port: 45628 TTL: 54 Packet length: 60 TOS: 0x00 This report was generated by: https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 14:50:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 10:50:33.151029 2026] [security2:error] [pid 2096688:tid 2096688] [client 157.52.92.73:28220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jwilder.com"] [uri "/.git/config"] [unique_id "al41ueYtX00CQj4i3kQ8rgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 12:15:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 08:15:16.384733 2026] [security2:error] [pid 22464:tid 22464] [client 157.52.92.73:25024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jesusthechristministry.org"] [uri "/.git/HEAD"] [unique_id "al4RVKcbRknZjQPcl_rlCAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 11:22:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:21:56.171928 2026] [security2:error] [pid 854:tid 854] [client 157.52.92.73:50588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hydrogenplus.net"] [uri "/.git/config"] [unique_id "al4E1JuW33qwZRx8nUtT-wAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 08:09:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 04:09:25.346096 2026] [security2:error] [pid 2558412:tid 2558412] [client 157.52.92.73:44686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brupharm.net"] [uri "/.git/config"] [unique_id "al3XtfOoalAyXb-0fDVGpAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack