๐ซ๐ท
mail.avx.gr
2026-07-27 15:38:33
(16 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 172.111.80.79 - - [22/Jul/20 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 172.111.80.79 - - [22/Jul/2026:19:22:23 +0300] "GET /.git/config HTTP/1.1" 403 2426 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 10:37:17
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:37:13.620046 2026] [security2:error] [pid 31592:tid 31592] [client 172.111.80.79:35024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sroberts.net"] [uri "/.git/HEAD"] [unique_id "amc02XVFBJctZOABDFb8ywAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 10:18:49
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:18:42.828032 2026] [security2:error] [pid 3645474:tid 3645474] [client 172.111.80.79:48518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ladymfashion.com"] [uri "/.git/HEAD"] [unique_id "amcwghG-PiKRPGIrxD5l4wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-26 13:49:04
(1 day ago)
172.111.80.79 - - [26/Jul/2026:16:49:03 +0300] "GET /.git/config HTTP/1.1" 404 1048 "-" "Mozilla/5.0 ...
show more
172.111.80.79 - - [26/Jul/2026:16:49:03 +0300] "GET /.git/config HTTP/1.1" 404 1048 "-" "Mozilla/5.0 (iPad; CPU OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1"
172.111.80.79 - - [26/Jul/2026:16:49:04 +0300] "GET /.git/config HTTP/1.1" 404 1048 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 11:20:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 07:20:16.171083 2026] [security2:error] [pid 3025354:tid 3025354] [client 172.111.80.79:56548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.comobarbershop.com"] [uri "/.git/HEAD"] [unique_id "amXtcBfpt4VaO3zHwqXQ3AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 19:28:30
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 15:28:24.829659 2026] [security2:error] [pid 30534:tid 30534] [client 172.111.80.79:43134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kaplankrew.com"] [uri "/.git/HEAD"] [unique_id "amEZ2K727FEpVpwGqYeqZAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-22 16:22:24
(5 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 172.111.80.79 - - [22/Jul/20 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 172.111.80.79 - - [22/Jul/2026:19:22:23 +0300] "GET /.git/config HTTP/1.1" 403 2426 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
Anonymous
2026-07-22 11:59:16
(5 days ago)
172.111.80.79 - - [22/Jul/2026:11:59:16 +0000] "GET /.git/config HTTP/1.1" 404 7802 "-" "Mozilla/5.0 ...
show more
172.111.80.79 - - [22/Jul/2026:11:59:16 +0000] "GET /.git/config HTTP/1.1" 404 7802 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 09:57:21
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 05:57:14.113072 2026] [security2:error] [pid 640301:tid 640301] [client 172.111.80.79:62612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "resume.marat.info"] [uri "/.git/HEAD"] [unique_id "amCT-pKdig81OV2dJ9d-ngAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-21 23:21:21
(6 days ago)
Try to access /.git/HEAD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 05:33:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 01:32:57.216330 2026] [security2:error] [pid 19385:tid 19385] [client 172.111.80.79:49504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rubypines.com"] [uri "/.git/HEAD"] [unique_id "al8EiaVGOmAq9ehFEqftBQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 00:24:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:24:46.091778 2026] [security2:error] [pid 3709364:tid 3709364] [client 172.111.80.79:27598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "basselier.com"] [uri "/.git/HEAD"] [unique_id "al68TkVy0n2OGFF-4aPlQQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 22:22:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 18:22:49.698343 2026] [security2:error] [pid 16727:tid 16727] [client 172.111.80.79:57246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.callbobh.com"] [uri "/.git/HEAD"] [unique_id "al6fuQfLcKA3cp54gnJCfgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 18:28:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 14:28:29.194556 2026] [security2:error] [pid 24095:tid 24095] [client 172.111.80.79:65486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.buyperfumeonline.net"] [uri "/.git/HEAD"] [unique_id "al5ozUuAnYeOlknVtBPSQwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 14:54:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.80.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 10:54:33.848357 2026] [security2:error] [pid 28358:tid 28358] [client 172.111.80.79:57544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tci.land"] [uri "/.git/config"] [unique_id "al42qbFVxWiUiuJEUs4nfwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack