🇺🇸
rdpguard.com
2026-08-26 00:23:23
(3 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
🇺🇦
URAN Publishing Service
2026-08-25 17:05:15
(4 days ago)
[25/Aug/2026:20:05:14 +0300] -- 158.173.79.238 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack
🇺🇸
CBJ
2026-08-25 15:31:08
(4 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
🇳🇱
e.fierstra
2026-08-25 14:56:44
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-08-25 13:33:56
(4 days ago)
cloudlinux2 fail2ban: 2026-08-25 15:29:47,599 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-25 15:29:47,599 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 194.243.14.219 - 2026-08-25 15:29:47cloudlinux2 fail2ban: 2026-08-25 15:29:57,249 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 45.157.112.232 - 2026-08-25 15:29:57cloudlinux2 fail2ban: 2026-08-25 15:29:57,036 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 45.157.112.232 - 2026-08-25 15:29:57cloudlinux2 fail2ban: 2026-08-25 15:30:12,715 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 194.146.92.8 - 2026-08-25 15:30:12cloudlinux2 fail2ban: 2026-08-25 15:30:06,309 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 130.49.115.96 - 2026-08-25 15:30:05cloudlinux2 fail2ban: 2026-08-25 15:30:10,777 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 49.47.243.134 - 2026-08-25 15:30:10cloudlinux2 fail2ban: 2026-08-25 15:30:21,835 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 49.47.243.134 - 2026-08-25 15:
show less
Web App Attack
🇮🇹
Inartis
2026-08-25 13:20:16
(4 days ago)
158.173.79.238 - - [25/Aug/2026:15:20:15 +0200] "GET /.git/config HTTP/1.1" 302 409 "-" "Go-http-cli ...
show more
158.173.79.238 - - [25/Aug/2026:15:20:15 +0200] "GET /.git/config HTTP/1.1" 302 409 "-" "Go-http-client/1.1"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-08-25 12:33:25
(4 days ago)
Bad bot ignoring robot.txt
Bad Web Bot
🇬🇧
WebNiraj
2026-08-25 10:52:11
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 158.173.79.238 (LT/Lithuania/-): 5 in the last ...
show more
(mod_security) mod_security (id:949110) triggered by 158.173.79.238 (LT/Lithuania/-): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-08-25 10:30:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:30:14.784114 2026] [security2:error] [pid 19502:tid 19502] [client 158.173.79.238:59229] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "velocitymech.com"] [uri "/.git/config"] [unique_id "ao1utlqLQ8Qz25Gks_yJMAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 09:45:25
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:45:17.822228 2026] [security2:error] [pid 6945:tid 6945] [client 158.173.79.238:34385] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schonuniverse.com"] [uri "/.git/config"] [unique_id "ao1kLe_N92FFhuWFfAx-CAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 09:23:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:23:11.749885 2026] [security2:error] [pid 30427:tid 30427] [client 158.173.79.238:40835] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primacomm.com"] [uri "/.git/config"] [unique_id "ao1e_yTSGu9IAmIAJ3ZqRQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 08:09:01
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 04:08:54.997503 2026] [security2:error] [pid 14993:tid 14993] [client 158.173.79.238:28183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "krmartindale.com"] [uri "/.git/config"] [unique_id "ao1NluqHt2rDJq6KjrAy4QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 07:30:34
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:30:27.007965 2026] [security2:error] [pid 2303:tid 2303] [client 158.173.79.238:25577] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gcmmortgage.com"] [uri "/.git/config"] [unique_id "ao1Ek-LT-K4EVdQ2E06MEQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 06:28:26
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.173.79.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 02:28:18.291619 2026] [security2:error] [pid 20889:tid 20889] [client 158.173.79.238:59269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "csm-dtc.com"] [uri "/.git/config"] [unique_id "ao02AnQsH0e0SqRxl7OjegAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
on-com
2026-08-25 05:30:44
(4 days ago)
URL scan
Brute-Force
Web App Attack