๐บ๐ธ
TPI-Abuse
2026-09-20 20:32:15
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:32:08.813572 2026] [security2:error] [pid 15867:tid 15867] [client 192.3.228.87:53687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tecnoconce.com"] [uri "/.git/HEAD"] [unique_id "arBCyFyGgAq5oKzupzh4hQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-19 21:59:32
(23 hours ago)
Auto-ban: >3000 req/min op 2026-09-19
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 14:29:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 10:29:41.916428 2026] [security2:error] [pid 29297:tid 29331] [client 192.3.228.87:54014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "illianapartyrentals.com"] [uri "/.git/HEAD"] [unique_id "aq6cVTL0j2OzDx7hnM1OsAAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-19 02:38:04
(1 day ago)
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 192.3.228.87 - - [19/Sep/2026:04:37:53 +0200] "GET /.git/HEAD HTTP/1.1" 403 7464 "-" "Python-urllib/3.10"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-19 00:18:57
(1 day ago)
cloudlinux2 fail2ban: 2026-09-19 02:13:49,417 fail2ban.filter [1813]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-19 02:13:49,417 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 192.3.228.87 - 2026-09-19 02:13:49cloudlinux2 fail2ban: 2026-09-19 02:14:04,965 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 173.234.154.193 - 2026-09-19 02:14:04cloudlinux2 fail2ban: 2026-09-19 02:14:10,903 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 23.108.93.51 - 2026-09-19 02:14:10cloudlinux2 fail2ban: 2026-09-19 02:14:35,422 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 182.8.195.74 - 2026-09-19 02:14:35cloudlinux2 fail2ban: 2026-09-19 02:15:51,026 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 182.8.195.74 - 2026-09-19 02:15:51cloudlinux2 fail2ban: 2026-09-19 02:15:51,136 fail2ban.filter [1813]: INFO [recidive] Found 182.8.195.74 - 2026-09-19 02:15:51cloudlinux2 fail2ban: 2026-09-19 02:15:51,130 fail2ban.actions [1813]: NOTICE [plesk-modsecurity] Ban 182.8.195.74cloudlinux2 fail2ban: 2026-09-19
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-18 14:48:15
(2 days ago)
[18/Sep/2026:17:48:15 +0300] -- 192.3.228.87 Ban reason: User-Agent Python-urllib
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 09:37:17
(5 days ago)
(mod_security) mod_security (id:949110) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.co ...
show more
(mod_security) mod_security (id:949110) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:37:09.516055 2026] [security2:error] [pid 3474:tid 3474] [client 192.3.228.87:47873] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.likulikubookings.com"] [uri "/.git/HEAD"] [unique_id "aqkRxWYE_9g0nnyHHOVFvwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-15 04:18:51
(5 days ago)
cloudlinux2 fail2ban: 2026-09-15 06:14:29,229 fail2ban.filter [1908]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-15 06:14:29,229 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 136.144.33.215 - 2026-09-15 06:14:28cloudlinux2 fail2ban: 2026-09-15 06:14:38,646 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 34.59.70.34 - 2026-09-15 06:14:38cloudlinux2 fail2ban: 2026-09-15 06:14:33,792 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 146.148.34.218 - 2026-09-15 06:14:33cloudlinux2 fail2ban: 2026-09-15 06:14:38,609 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 192.3.228.87 - 2026-09-15 06:14:38cloudlinux2 fail2ban: 2026-09-15 06:16:04,078 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Unban 223.185.26.253cloudlinux2 fail2ban: 2026-09-15 06:16:15,060 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 49.47.241.178 - 2026-09-15 06:16:15cloudlinux2 fail2ban: 2026-09-15 06:17:09,824 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 49.47.241.178 - 2026-09-15 06:17:09cloudlinux2 fail2ba
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 19:58:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 15:58:45.210696 2026] [security2:error] [pid 3566978:tid 3566982] [client 192.3.228.87:48353] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "metropolitanbasel.org.metropolitanbasel.org"] [uri "/.git/HEAD"] [unique_id "aqcAdXfaLFLQaVGUOK_uZAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-12 23:10:25
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 20:50:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 16:50:08.847008 2026] [security2:error] [pid 28650:tid 28650] [client 192.3.228.87:46010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nysasports.com"] [uri "/.git/HEAD"] [unique_id "aqW7AJm-0oeLHtZg_kcuKwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-12 12:56:28
(1 week ago)
192.3.228.87 - - [12/Sep/2026:14:56:28 +0200] "GET /.git/HEAD HTTP/1.1" 301 6184 "-" "Python-urllib/ ...
show more
192.3.228.87 - - [12/Sep/2026:14:56:28 +0200] "GET /.git/HEAD HTTP/1.1" 301 6184 "-" "Python-urllib/3.10"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 12:55:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:55:20.957013 2026] [security2:error] [pid 8028:tid 8028] [client 192.3.228.87:39930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.goldengatecorgis.org"] [uri "/.git/HEAD"] [unique_id "aqVLuImjKdttqIKs4dKlRQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 12:55:02
(1 week ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 12:04:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 192.3.228.87 (192-3-228-87-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:04:05.507253 2026] [security2:error] [pid 11846:tid 11846] [client 192.3.228.87:38006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kritaka.ai"] [uri "/.git/HEAD"] [unique_id "aqFLNWD0SfV9vgAuCGRLiQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack