๐ซ๐ท
mail.avx.gr
2026-07-23 11:29:35
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 157.52.92.91 - - [19/Jul/202 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 157.52.92.91 - - [19/Jul/2026:06:32:49 +0300] "GET /.git/config HTTP/1.1" 403 2428 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0"
show less
Web App Attack
๐ซ๐ท
masterguru
2026-07-22 14:22:44
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-07-22 09:34:41
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 00:04:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 20:04:38.662203 2026] [security2:error] [pid 48539:tid 48539] [client 157.52.92.91:40410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldengatecorgis.org"] [uri "/.git/HEAD"] [unique_id "amAJFqvl8wxRQLLtWA0PWgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 23:01:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 19:01:25.704050 2026] [security2:error] [pid 18997:tid 18997] [client 157.52.92.91:38764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kentsavagelaw.com"] [uri "/.git/HEAD"] [unique_id "al_6RdWkrWUH16460EtkbwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-21 22:53:58
(2 days ago)
cloudlinux2 fail2ban: 2026-07-22 00:49:41,141 fail2ban.filter [1927]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-22 00:49:41,141 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 136.144.42.25 - 2026-07-22 00:49:40cloudlinux2 fail2ban: 2026-07-22 00:51:27,536 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 185.223.152.28 - 2026-07-22 00:51:27cloudlinux2 fail2ban: 2026-07-22 00:51:22,443 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 172.98.32.162 - 2026-07-22 00:51:21cloudlinux2 fail2ban: 2026-07-22 00:51:28,290 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 185.223.152.27 - 2026-07-22 00:51:27cloudlinux2 fail2ban: 2026-07-22 00:52:09,261 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 157.52.92.91 - 2026-07-22 00:52:09cloudlinux2 fail2ban: 2026-07-22 00:52:09,976 fail2ban.filter [1927]: INFO [recidive] Found 157.52.92.91 - 2026-07-22 00:52:09cloudlinux2 fail2ban: 2026-07-22 00:52:08,320 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 157.52.92.91 - 2026-07-22 00:52:08cloudlinux2 f
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 21:19:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 17:19:48.486406 2026] [security2:error] [pid 7210:tid 7210] [client 157.52.92.91:39786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mysticalparadise.com"] [uri "/.git/HEAD"] [unique_id "al_idNIBd0ODN6ZHJg4IMQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-21 20:36:44
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 18:52:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:52:52.923298 2026] [security2:error] [pid 276445:tid 276445] [client 157.52.92.91:9258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fedeoliva.cl"] [uri "/.git/HEAD"] [unique_id "al_ABHv1Mzf5aTEiu7NSgwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-21 16:12:17
(3 days ago)
csagent: score 19.1: secrets grab x2; 2 domain(s) in 16s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 14:05:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 10:05:35.197623 2026] [security2:error] [pid 3394:tid 3456] [client 157.52.92.91:32610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.newsrank.us"] [uri "/.git/HEAD"] [unique_id "al98r6-pysBh9D0IEjjuBAAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:33:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:33:10.547095 2026] [security2:error] [pid 554608:tid 554608] [client 157.52.92.91:23378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ellestark.com"] [uri "/.git/HEAD"] [unique_id "al9nBjnFm-Shexoe8N40cgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 10:46:58
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 06:46:50.065809 2026] [security2:error] [pid 18945:tid 18945] [client 157.52.92.91:49306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rotarymagnetics.com"] [uri "/.git/HEAD"] [unique_id "al9OGqcytVU7mlGpUWHdjQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 04:31:38
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฟ๐ฆ
conure
2026-07-21 00:38:00
(3 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack