๐บ๐ธ
CBJ
2026-07-23 10:03:05
(2 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 09:31:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:31:35.894249 2026] [security2:error] [pid 15478:tid 15478] [client 167.82.167.31:46278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.brownlegacy.org"] [uri "/.git/HEAD"] [unique_id "amHfd3MtSehzB-T5mAdsSAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 09:08:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:08:25.697347 2026] [security2:error] [pid 494226:tid 494226] [client 167.82.167.31:9630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "communityofthecosmos.org"] [uri "/.git/HEAD"] [unique_id "amHaCcj7wY1AUJfoVhxQNwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 08:48:49
(2 days ago)
(caddyscan) Scanner path probe from 167.82.167.31 (US/United States/-): 5 in the last 3600 secs; Por ...
show more
(caddyscan) Scanner path probe from 167.82.167.31 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 167.82.167.31 - - [23/Jul/2026:08:48:45 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 167.82.167.31 - - [23/Jul/2026:08:48:45 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 167.82.167.31 - - [23/Jul/2026:08:48:45 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 167.82.167.31 - - [23/Jul/2026:08:48:46 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 167.82.167.31 - - [23/Jul/2026:08:48:46 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-23 08:41:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 04:41:46.157840 2026] [security2:error] [pid 328391:tid 328391] [client 167.82.167.31:49694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.buggyshop.org"] [uri "/.git/HEAD"] [unique_id "amHTykx0R8-Rpe71VBA4OwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-07-23 08:07:55
(2 days ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
Anonymous
2026-07-23 04:31:57
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
Anonymous
2026-07-23 00:14:56
(2 days ago)
167.82.167.31 - - [22/Jul/2026:21:14:55 -0300] "GET /.git/HEAD HTTP/1.1" 403 1810 "-" "Mozilla/5.0 ( ...
show more
167.82.167.31 - - [22/Jul/2026:21:14:55 -0300] "GET /.git/HEAD HTTP/1.1" 403 1810 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
Anonymous
2026-07-22 23:55:01
(2 days ago)
suspicious request in access.log
Web App Attack
๐ง๐ท
borbolla
2026-07-22 23:54:46
(2 days ago)
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.git/HEAD HTTP/1.1" "GET ...
show more
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.git/HEAD HTTP/1.1" "GET /.git/config HTTP/1.1"
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-22 23:49:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:49:11.176861 2026] [security2:error] [pid 30204:tid 30204] [client 167.82.167.31:57508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centerofhopefl.com.tribecalledfamilypodcast.org"] [uri "/.git/HEAD"] [unique_id "amFW96XVZHpxUU3LllCykwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 23:35:14
(2 days ago)
(caddyscan) Scanner path probe from 167.82.167.31 (US/United States/-): 5 in the last 3600 secs; Por ...
show more
(caddyscan) Scanner path probe from 167.82.167.31 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 167.82.167.31 - - [22/Jul/2026:23:35:09 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 167.82.167.31 - - [22/Jul/2026:23:35:09 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 167.82.167.31 - - [22/Jul/2026:23:35:09 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 167.82.167.31 - - [22/Jul/2026:23:35:09 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 167.82.167.31 - - [22/Jul/2026:23:35:09 +0000] "GET /.git/HEAD HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-22 23:29:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:29:09.235185 2026] [security2:error] [pid 2195802:tid 2195802] [client 167.82.167.31:52722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oruguitas.org"] [uri "/.git/HEAD"] [unique_id "amFSReIWXGiHSIFJI_A0EQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 23:09:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:09:41.700692 2026] [security2:error] [pid 1447441:tid 1447441] [client 167.82.167.31:2470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "advantagept.org"] [uri "/.git/HEAD"] [unique_id "amFNtbrglYKzwjOTiYWvPwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-22 22:55:04
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack