๐ซ๐ท
mail.avx.gr
2026-07-23 11:29:33
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 157.52.92.75 - - [18/Jul/2026:07:51:01 +0300] "GE ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 157.52.92.75 - - [18/Jul/2026:07:51:01 +0300] "GET /.git/HEAD HTTP/1.1" 403 6280 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
๐ซ๐ท
masterguru
2026-07-22 18:41:54
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-22 18:20:30
(2 days ago)
Try to access /.git/HEAD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 13:53:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 09:53:50.847515 2026] [security2:error] [pid 25452:tid 25452] [client 157.52.92.75:42172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grupogasa.com"] [uri "/.git/HEAD"] [unique_id "amDLbmPVhA3lPYqGBnkQuQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Eric
2026-07-22 12:23:27
(2 days ago)
[Wed Jul 22 12:22:44.296808 2026] [security2:error] [pid 1867583:tid 1867583] [client 157.52.92.75:1 ...
show more
[Wed Jul 22 12:22:44.296808 2026] [security2:error] [pid 1867583:tid 1867583] [client 157.52.92.75:11926] [client 157.52.92.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/.git/HEAD"] [unique_id "amC2FM2qpkTHJSMI8xSlywAAAAA"]
[Wed Jul 22 12:22:45.607871 2026] [security2:error] [pid 1867583:tid 1867583] [client 157.52.92.75:11926] [client 157.52.92.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severi
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 02:16:40
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 22:16:33.325360 2026] [security2:error] [pid 178958:tid 178958] [client 157.52.92.75:21064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ucommsi.com"] [uri "/.git/HEAD"] [unique_id "amAoAe77FH89misxI6aFEAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-21 23:52:08
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-07-21 15:47:12
(3 days ago)
2026/07/21 15:47:09 [error] 4730#4730: *95620 [client 157.52.92.75] ModSecurity: Access denied with ...
show more
2026/07/21 15:47:09 [error] 4730#4730: *95620 [client 157.52.92.75] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.28.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "smscoreapi.ingeltechgh.com"] [uri "/.git/HEAD"] [unique_id "178464882986.147195"] [ref ""], client: 157.52.92.75, server: srv.ingeltechgh.com, request: "GET /.git/HEAD HTTP/1.1", host: "smscoreapi.ingeltechgh.com"
2026/07/21 15:47:09 [error] 4730#4730: *95620 [client 157.52.92.75] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/lo
...
show less
Brute-Force
๐จ๐ญ
TheCoon
2026-07-21 15:30:01
(3 days ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-21 15:14:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 11:13:59.750814 2026] [security2:error] [pid 3396:tid 3526] [client 157.52.92.75:47078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.honeyled.com"] [uri "/.git/HEAD"] [unique_id "al-Mt3N0leyzQIlwN8KaaQAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 13:07:32
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 09:07:26.234323 2026] [security2:error] [pid 30616:tid 30616] [client 157.52.92.75:8740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.frightlibrary.org"] [uri "/.git/HEAD"] [unique_id "al9vDuaVGFJgdjquEALMDgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:22:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:22:25.803466 2026] [security2:error] [pid 25038:tid 25038] [client 157.52.92.75:19078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.faithlines.com"] [uri "/.git/HEAD"] [unique_id "al9kgZ1n8SMANUn-p5kiTAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-21 12:11:26
(3 days ago)
csagent: score 19.7: secrets grab x2, 404 noise floor x1; 2 domain(s) in 9s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:46:07
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:46:02.510291 2026] [security2:error] [pid 31614:tid 31614] [client 157.52.92.75:64018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.goatedlottosecrets.com"] [uri "/.git/HEAD"] [unique_id "al6zOmXFou2mhN5pcqQjHgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:16:42
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.75 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:16:38.801557 2026] [security2:error] [pid 3660046:tid 3660046] [client 157.52.92.75:43360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hogprinter.com"] [uri "/.git/HEAD"] [unique_id "al6sViijvowU6S6KgeuZgwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack