๐ณ๐ฑ
Alt255
2026-09-24 17:46:30
(2 hours ago)
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 198.11.53.122 - - [24/Sep/2026:19:46:17 +0200] "GET /.git/config HTTP/1.1" 301 626 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-24 17:06:24
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 16:22:52
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 12:22:36.856410 2026] [security2:error] [pid 9624:tid 9624] [client 198.11.53.122:56615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emilybaotrannguyen.com"] [uri "/.git/HEAD"] [unique_id "arVOTN9pSP1E5ewoHckWHgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 14:37:38
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 10:37:22.356612 2026] [security2:error] [pid 6594:tid 6594] [client 198.11.53.122:54963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drlaurengardner.com"] [uri "/.git/HEAD"] [unique_id "arU1otn6p12aiyoQRhIc-gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 13:03:30
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 09:03:14.611254 2026] [security2:error] [pid 28038:tid 28038] [client 198.11.53.122:56749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "herston.us"] [uri "/.git/HEAD"] [unique_id "arUfkslzcU0M7FeZtc2TpgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 12:16:29
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 08:16:24.079392 2026] [security2:error] [pid 14789:tid 14789] [client 198.11.53.122:36313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biblestudentfiles.org"] [uri "/.git/config"] [unique_id "arUUmNIGN98y5p4nQpoZxwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 11:46:05
(8 hours ago)
Web scanner: GET /.git/HEAD
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 11:33:21
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 07:33:04.283769 2026] [security2:error] [pid 12100:tid 12100] [client 198.11.53.122:59949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenorwoods.name"] [uri "/.git/HEAD"] [unique_id "arUKcEjRsytFIJJmq9Qe0gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-24 11:11:22
(8 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
๐บ๐ธ
LSPCCU
2026-09-24 11:00:32
(8 hours ago)
TSEC Honeypot Network report. Threat score: 82/100. Categories: DDoS Attack, Port Scan, Hacking, Bru ...
show more
TSEC Honeypot Network report. Threat score: 82/100. Categories: DDoS Attack, Port Scan, Hacking, Brute-Force, Web App Attack, SSH, IoT Targeted. Honeypot: galah. Context: 198.11.53.122 classified as botnet node participating in coordinated attack campaigns (high confidence).
show less
DDoS Attack
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
IoT Targeted
๐บ๐ธ
TPI-Abuse
2026-09-24 08:59:12
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:58:57.837403 2026] [security2:error] [pid 19651:tid 19651] [client 198.11.53.122:40337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "electricmeatgrinder.com"] [uri "/.git/HEAD"] [unique_id "arTmUVt3KB9K7OUfkJvTOwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:26:13
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:26:00.390685 2026] [security2:error] [pid 17588:tid 17611] [client 198.11.53.122:48963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barrywillis.org"] [uri "/.git/HEAD"] [unique_id "arTemLIf0L-qbTuWTlgFXQAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-24 07:53:57
(11 hours ago)
cloudlinux2 fail2ban: 2026-09-24 09:48:52,901 fail2ban.filter [1603]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-24 09:48:52,901 fail2ban.filter [1603]: INFO [plesk-wordpress] Found 91.193.232.233 - 2026-09-24 09:48:52cloudlinux2 fail2ban: 2026-09-24 09:49:38,465 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 198.11.53.122 - 2026-09-24 09:49:38cloudlinux2 fail2ban: 2026-09-24 09:51:31,742 fail2ban.filter [1603]: INFO [plesk-wordpress] Found 173.239.213.54 - 2026-09-24 09:51:30cloudlinux2 fail2ban: 2026-09-24 09:51:47,075 fail2ban.actions [1603]: NOTICE [plesk-modsecurity] Unban 103.137.71.190cloudlinux2 fail2ban: 2026-09-24 09:52:23,745 fail2ban.actions [1603]: NOTICE [plesk-modsecurity] Ban 35.194.220.84cloudlinux2 fail2ban: 2026-09-24 09:52:22,165 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 35.194.220.84 - 2026-09-24 09:52:22cloudlinux2 fail2ban: 2026-09-24 09:52:22,902 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 35.194.220.84 - 2026-09-24 09:52:22cloudlinux2 fail2ban: 2026-09-24 09:52:23,
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-24 07:43:14
(12 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 198.11.53.122 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 198.11.53.122 (US/United States/-): 2 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-09-24 07:08:03
(12 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack