๐ซ๐ท
mail.avx.gr
2026-07-23 11:29:34
(2 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 157.52.92.82 - - [19/Jul/202 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 157.52.92.82 - - [19/Jul/2026:12:07:47 +0300] "GET /.git/config HTTP/1.1" 403 2424 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 19:59:56
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 15:59:48.850552 2026] [security2:error] [pid 3791939:tid 3791939] [client 157.52.92.82:60008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graydortmotors.com"] [uri "/.git/HEAD"] [unique_id "amEhNER3jIGDmu1JyKqt3wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 19:07:51
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 15:07:47.033744 2026] [security2:error] [pid 1262956:tid 1262956] [client 157.52.92.82:41046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rigavit.com"] [uri "/.git/HEAD"] [unique_id "amEVA69GxCGP7OXfTOEGnwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-22 15:17:03
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 14:08:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 10:08:29.811530 2026] [security2:error] [pid 1162909:tid 1162909] [client 157.52.92.82:27734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alianzafreight.com"] [uri "/.git/HEAD"] [unique_id "amDO3REQGHhll23FfiGslAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 12:30:38
(1 day ago)
2026/07/21 18:03:04 [error] 4721#4721: *98810 [client 157.52.92.82] ModSecurity: Access denied with ...
show more
2026/07/21 18:03:04 [error] 4721#4721: *98810 [client 157.52.92.82] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.28.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "abii-reporting-api.ingeltechgh.com"] [uri "/.git/HEAD"] [unique_id "17846569848.821943"] [ref ""], client: 157.52.92.82, server: srv.ingeltechgh.com, request: "GET /.git/HEAD HTTP/1.1", host: "abii-reporting-api.ingeltechgh.com"
2026/07/21 18:03:05 [error] 4721#4721: *98810 [client 157.52.92.82] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' )
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-21 17:37:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 13:37:53.178184 2026] [security2:error] [pid 179174:tid 179174] [client 157.52.92.82:29284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.batonrougecustomcabinets.com"] [uri "/.git/HEAD"] [unique_id "al-ucS1H22X6j56D8QdQXwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 16:39:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 12:38:53.897561 2026] [security2:error] [pid 17910:tid 17910] [client 157.52.92.82:54640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.evannine.com"] [uri "/.git/HEAD"] [unique_id "al-gncW1D6oSPtpS306NlwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 11:21:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:21:18.796127 2026] [security2:error] [pid 3707943:tid 3707943] [client 157.52.92.82:19878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.gormish.org"] [uri "/.git/HEAD"] [unique_id "al9WLouTlccfKcmuSMhBSAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 00:12:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:11:59.954267 2026] [security2:error] [pid 17180:tid 17180] [client 157.52.92.82:20282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ecrecorp.com"] [uri "/.git/HEAD"] [unique_id "al65T7-PusN0rKnp_EES6AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:34:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:34:43.222777 2026] [security2:error] [pid 3198:tid 3198] [client 157.52.92.82:43318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "volkerjahn.name"] [uri "/.git/HEAD"] [unique_id "al6wkzA-nYBxg21uMwUWHwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-20 21:59:05
(2 days ago)
Auto-ban: >3000 req/min op 2026-07-20
Web App Attack
SSH
Hacking
๐ซ๐ท
masterguru
2026-07-20 18:53:15
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 18:52:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 14:52:21.248903 2026] [security2:error] [pid 1230596:tid 1230596] [client 157.52.92.82:58224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.osmanhc.com"] [uri "/.git/HEAD"] [unique_id "al5uZdOVjAIv0-sjfqrcXAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-07-20 18:25:06
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack