๐ฎ๐น
CoreTech srl
2026-07-22 19:43:57
(3 days ago)
cloudlinux2 fail2ban: 2026-07-22 21:39:13,353 fail2ban.filter [1589]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-22 21:39:13,353 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 157.52.92.65 - 2026-07-22 21:39:13cloudlinux2 fail2ban: 2026-07-22 21:39:14,391 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 157.52.92.65 - 2026-07-22 21:39:14cloudlinux2 fail2ban: 2026-07-22 21:39:13,679 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 157.52.92.65 - 2026-07-22 21:39:13cloudlinux2 fail2ban: 2026-07-22 21:39:14,872 fail2ban.actions [1589]: NOTICE [plesk-modsecurity] Ban 157.52.92.65cloudlinux2 fail2ban: 2026-07-22 21:39:14,879 fail2ban.filter [1589]: INFO [recidive] Found 157.52.92.65 - 2026-07-22 21:39:14cloudlinux2 fail2ban: 2026-07-22 21:39:20,960 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 213.232.121.176 - 2026-07-22 21:39:20cloudlinux2 fail2ban: 2026-07-22 21:39:14,763 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 157.52.92.65 - 2026-07-22 21:39:14cloudlinux2 fail2ban: 2026-07-22
show less
Web App Attack
๐บ๐ธ
MPL
2026-07-21 12:43:54
(4 days ago)
tcp/443 (4 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-21 11:49:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:49:50.503589 2026] [security2:error] [pid 11589:tid 11589] [client 172.111.91.45:19456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ic1surplus.com"] [uri "/.git/HEAD"] [unique_id "al9c3oCKIhOrvEGK-pq97QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 11:25:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:25:48.329952 2026] [security2:error] [pid 16135:tid 16135] [client 172.111.91.45:9586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aivosminerals.com"] [uri "/.git/HEAD"] [unique_id "al9XPK0n1uYbeybDKWCfYgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:58:56
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:58:50.441207 2026] [security2:error] [pid 3704938:tid 3704938] [client 172.111.91.45:52002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thepotteriesmesilla.com"] [uri "/.git/HEAD"] [unique_id "al62OsWPrrUyqHMls4beYgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 22:56:26
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 18:56:21.560875 2026] [security2:error] [pid 9338:tid 9338] [client 172.111.91.45:57088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.babylontravelone.com"] [uri "/.git/HEAD"] [unique_id "al6nlecFqs-YpRD0jhpi2wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 19:18:00
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.111.91.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.111.91.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 15:17:55.715072 2026] [security2:error] [pid 9175:tid 9175] [client 172.111.91.45:23314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.bhgvh.com"] [uri "/.git/HEAD"] [unique_id "al50Yx2tXcnpmd2LhvB5pgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rip
2026-07-19 22:27:25
(6 days ago)
Restricted File Access Attempts
Port Scan
Web App Attack