๐บ๐ธ
TPI-Abuse
2026-07-23 09:55:47
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:55:39.789715 2026] [security2:error] [pid 2894339:tid 2894339] [client 167.82.167.20:13468] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "donate.freedrm.org"] [uri "/.git/HEAD"] [unique_id "amHlG-A5DEAMrMJode-XzwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 09:21:28
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:21:19.441286 2026] [security2:error] [pid 3124512:tid 3124540] [client 167.82.167.20:7210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.advertisingfirm.org"] [uri "/.git/HEAD"] [unique_id "amHdDz-rmKTsmcPF5W1QYQAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 09:05:41
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:05:33.989818 2026] [security2:error] [pid 2401373:tid 2401373] [client 167.82.167.20:54064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloggersunlimited.com.joshuashands.org"] [uri "/.git/HEAD"] [unique_id "amHZXYUwFJBuOVflRUz1mAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 08:37:28
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 04:37:22.227174 2026] [security2:error] [pid 2003972:tid 2003972] [client 167.82.167.20:41028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artspacecleveland.com.artspacecleveland.org"] [uri "/.git/HEAD"] [unique_id "amHSwuoLxbWu9BVTbbH9wQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ISPLtd
2026-07-23 07:49:50
(8 hours ago)
167.82.167.20 [23/Jul/2026:04:49:49 -0300] beta.target.domain.ca:443 URL:/.git/HEAD "GET /.git/HEAD
...
show more
167.82.167.20 [23/Jul/2026:04:49:49 -0300] beta.target.domain.ca:443 URL:/.git/HEAD "GET /.git/HEAD
167.82.167.20 [23/Jul/2026:04:49:50 -0300] beta.target.domain.ca:443 URL:/.git/HEAD "GET /.git/HEAD
...
show less
Hacking
Web App Attack
๐ฉ๐ช
Trueforce Threat Report
2026-07-23 07:46:00
(8 hours ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 04:32:11
(11 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ง๐ท
borbolla
2026-07-23 00:16:52
(15 hours ago)
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.git/HEAD HTTP/1.1"
Web App Attack
Bad Web Bot
Anonymous
2026-07-23 00:09:30
(15 hours ago)
167.82.167.20 - - [22/Jul/2026:21:09:29 -0300] "GET /.git/HEAD HTTP/1.1" 403 1810 "-" "Mozilla/5.0 ( ...
show more
167.82.167.20 - - [22/Jul/2026:21:09:29 -0300] "GET /.git/HEAD HTTP/1.1" 403 1810 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
Anonymous
2026-07-23 00:00:20
(16 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
CBJ
2026-07-22 23:31:12
(16 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 23:26:51
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:26:43.986378 2026] [security2:error] [pid 8251:tid 8251] [client 167.82.167.20:15248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.accordionclub.org"] [uri "/.git/HEAD"] [unique_id "amFRs5r23LXhdejKkITWLwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 23:11:16
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:11:12.552867 2026] [security2:error] [pid 1161113:tid 1161113] [client 167.82.167.20:59078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agkgt.org.ctsaagt.org"] [uri "/.git/HEAD"] [unique_id "amFOEPmNI7ypI4oXB_wADwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-22 22:55:04
(17 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-22 22:43:56
(17 hours ago)
cloudlinux2 fail2ban: 2026-07-23 00:41:14,911 fail2ban.filter [1589]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-23 00:41:14,911 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 167.82.167.30 - 2026-07-23 00:41:14cloudlinux2 fail2ban: 2026-07-23 00:41:30,266 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 167.82.167.20 - 2026-07-23 00:41:30cloudlinux2 fail2ban: 2026-07-23 00:41:31,847 fail2ban.actions [1589]: NOTICE [plesk-modsecurity] Ban 167.82.167.30cloudlinux2 fail2ban: 2026-07-23 00:41:29,190 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 167.82.167.30 - 2026-07-23 00:41:28cloudlinux2 fail2ban: 2026-07-23 00:41:23,061 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 167.82.167.21 - 2026-07-23 00:41:23cloudlinux2 fail2ban: 2026-07-23 00:41:29,545 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 167.82.167.24 - 2026-07-23 00:41:29cloudlinux2 fail2ban: 2026-07-23 00:41:32,470 fail2ban.filter [1589]: INFO [recidive] Found 167.82.167.20 - 2026-07-23 00:41:32cloudlinux2 fail2ban: 2026-0
show less
Brute-Force