Anonymous
2026-07-28 04:31:47
(17 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
mnsf
2026-07-27 22:05:30
(23 hours ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
Anonymous
2026-07-27 20:00:18
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ซ๐ท
masterguru
2026-07-27 19:57:49
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 19:21:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.16.43.98 (ec2-3-16-43-98.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 3.16.43.98 (ec2-3-16-43-98.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 15:20:52.523549 2026] [security2:error] [pid 1629995:tid 1629995] [client 3.16.43.98:36456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horsesaw.com"] [uri "/.git/config"] [unique_id "amevlOQ-85YgPisngrtz5AAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 18:55:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.16.43.98 (ec2-3-16-43-98.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 3.16.43.98 (ec2-3-16-43-98.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:55:28.588377 2026] [security2:error] [pid 823406:tid 823406] [client 3.16.43.98:48390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horseillustration.com"] [uri "/.git/config"] [unique_id "amepoIlexGxzg6qbe5ZQYAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-27 17:29:22
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ฎ
ManagedStack
2026-07-27 15:36:15
(1 day ago)
Wordpress Attack
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-07-27 15:35:52
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:31:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.16.43.98 (ec2-3-16-43-98.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 3.16.43.98 (ec2-3-16-43-98.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:31:12.640684 2026] [security2:error] [pid 20416:tid 20416] [client 3.16.43.98:43972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horizonsoundchicago.com"] [uri "/.git/config"] [unique_id "amd5wKtPcw0UOXGR4T82rgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-27 15:20:43
(1 day ago)
3.16.43.98 - - [27/Jul/2026:18:20:41 +0300] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Wi ...
show more
3.16.43.98 - - [27/Jul/2026:18:20:41 +0300] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.16.43.98 - - [27/Jul/2026:18:20:43 +0300] "GET /.env HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-07-27 13:05:48
(1 day ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (41/60 min)'; Requests=41
Port Scan
๐ณ๐ฑ
Site.eu
2026-07-27 06:38:15
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 04:38:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.16.43.98 (ec2-3-16-43-98.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 3.16.43.98 (ec2-3-16-43-98.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:38:49.396730 2026] [security2:error] [pid 3333167:tid 3333167] [client 3.16.43.98:48684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hopeforthefuture.africa.greenlight.us"] [uri "/.git/config"] [unique_id "ambg2f8jk7p4mzssxKqTewAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-26 21:59:33
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-25.
show less
Web App Attack
SSH
Hacking