Anonymous
2026-09-05 22:40:07
(1 week ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇮🇹
CoreTech srl
2026-09-05 20:18:56
(1 week ago)
cloudlinux2 fail2ban: 2026-09-05 22:14:09,998 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-05 22:14:09,998 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 183.251.241.83 - 2026-09-05 22:14:09cloudlinux2 fail2ban: 2026-09-05 22:14:57,353 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 142.111.152.109 - 2026-09-05 22:14:57cloudlinux2 fail2ban: 2026-09-05 22:15:16,972 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.186.178.37 - 2026-09-05 22:15:16cloudlinux2 fail2ban: 2026-09-05 22:15:17,535 fail2ban.filter [1594]: INFO [recidive] Found 34.186.178.37 - 2026-09-05 22:15:17cloudlinux2 fail2ban: 2026-09-05 22:15:17,371 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.186.178.37 - 2026-09-05 22:15:17cloudlinux2 fail2ban: 2026-09-05 22:15:16,801 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.186.178.37 - 2026-09-05 22:15:16cloudlinux2 fail2ban: 2026-09-05 22:15:17,530 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Ban 34.186.178.37cloudlinux2 fail2ban: 2026-
show less
Web App Attack
🇺🇸
Epimetheus
2026-09-05 07:34:03
(1 week ago)
Unauthorized access attempts:
[GET] /.git/config
UA: python-requests/2.22.0
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 07:08:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 03:07:58.604005 2026] [security2:error] [pid 26763:tid 26763] [client 167.172.92.95:52770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eta-mct.com"] [uri "/.git/config"] [unique_id "apu_zl9VygyWegbfqfchLAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-05 07:05:31
(1 week ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 00:29:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 20:29:39.279000 2026] [security2:error] [pid 17535:tid 17535] [client 167.172.92.95:45674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "essentialee.com"] [uri "/.git/config"] [unique_id "aptic_igeUzMV3kLzyfo7AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:02:02
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇨🇭
ALPHANET
2026-09-04 21:15:52
(1 week ago)
web exploits
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:35:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:35:12.242324 2026] [security2:error] [pid 2257:tid 2257] [client 167.172.92.95:42170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esneuro.net"] [uri "/.git/config"] [unique_id "apsrgInom-4XgjYqyhIJ4wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:21:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:21:46.178711 2026] [security2:error] [pid 2430:tid 2430] [client 167.172.92.95:50446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esendeniz.net"] [uri "/.git/config"] [unique_id "apsMOoXJIDguBRaV3ww6AQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:09:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:09:38.897895 2026] [security2:error] [pid 17046:tid 17046] [client 167.172.92.95:41438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esad.com"] [uri "/.git/config"] [unique_id "aprfMiYNtVYcTBWLxSSQKwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
SkyDancer
2026-09-04 13:42:33
(1 week ago)
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show more
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less
Hacking
Brute-Force
🇫🇮
Erpelstolz
2026-09-04 13:05:39
(1 week ago)
external host: 167.172.92.95 - - [04/Sep/2026:15:05:39 +0200] "GET /.git/config HTTP/1.1" 403 5614 " ...
show more
external host: 167.172.92.95 - - [04/Sep/2026:15:05:39 +0200] "GET /.git/config HTTP/1.1" 403 5614 "-" "python-requests/2.22.0" CF-Ray:- CF-IP:-
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:07:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:07:45.596340 2026] [security2:error] [pid 6265:tid 6265] [client 167.172.92.95:52884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ericeschenbach.com"] [uri "/.git/config"] [unique_id "apqKYdrFs9VFGrQJitfjgQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:48:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.92.95 (flymiracle.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:48:01.256098 2026] [security2:error] [pid 21025:tid 21025] [client 167.172.92.95:58318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ericadamsdesign.com"] [uri "/.git/config"] [unique_id "apqFwUaQSOY1SZG-PmxBjAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack