๐ฎ๐น
CoreTech srl
2026-08-25 17:43:57
(11 minutes ago)
cloudlinux2 fail2ban: 2026-08-25 19:38:51,551 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-25 19:38:51,551 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 136.70.127.72 - 2026-08-25 19:38:51cloudlinux2 fail2ban: 2026-08-25 19:38:49,909 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 136.70.127.72 - 2026-08-25 19:38:49cloudlinux2 fail2ban: 2026-08-25 19:38:55,672 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 167.71.122.107 - 2026-08-25 19:38:55cloudlinux2 fail2ban: 2026-08-25 19:39:44,629 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 34.126.174.31 - 2026-08-25 19:39:44cloudlinux2 fail2ban: 2026-08-25 19:40:15,514 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 136.85.87.251 - 2026-08-25 19:40:15cloudlinux2 fail2ban: 2026-08-25 19:40:19,434 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 34.80.55.214 - 2026-08-25 19:40:19cloudlinux2 fail2ban: 2026-08-25 19:41:14,079 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.160.21 - 2026-08-25 19:
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-25 17:11:48
(43 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 13:11:43.352185 2026] [security2:error] [pid 19927:tid 19927] [client 34.80.55.214:25242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "puduspoems.com"] [uri "/.git/config"] [unique_id "ao3MzyoSqkezyphe7wGYogAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-25 17:02:13
(52 minutes ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
Anonymous
2026-08-25 16:32:23
(1 hour ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 16:27:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 12:27:01.774465 2026] [security2:error] [pid 12090:tid 12090] [client 34.80.55.214:45694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lisarlee.com"] [uri "/.git/config"] [unique_id "ao3CVdTuL327CDR2A35NEwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-25 16:27:01
(1 hour ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 16:09:34
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 12:09:25.723417 2026] [security2:error] [pid 3384:tid 3384] [client 34.80.55.214:14460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jetpower.com"] [uri "/.git/config"] [unique_id "ao2-NSIscOlycjWazW-pFQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-25 15:58:17
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-08-25 15:58 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-08-25 15:55:11
(1 hour ago)
Login credentials theft attempt
Hacking
๐ฎ๐น
VHosting
2026-08-25 15:50:07
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 15:47:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 11:47:00.813646 2026] [security2:error] [pid 28275:tid 28275] [client 34.80.55.214:25116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalpackets.net"] [uri "/.git/config"] [unique_id "ao249Eyb1rEzNtKPY5m3owAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-25 15:35:50
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
inlink.ltd
2026-08-25 15:29:26
(2 hours ago)
dot file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 15:20:44
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 11:20:36.726152 2026] [security2:error] [pid 942:tid 942] [client 34.80.55.214:47004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dojoonthego.com"] [uri "/.git/config"] [unique_id "ao2yxDIRcrUSR8RbunT0IwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 15:02:18
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.55.214 (214.55.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 11:02:14.274411 2026] [security2:error] [pid 30258:tid 30258] [client 34.80.55.214:3744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "charityholidaycards.com"] [uri "/.git/config"] [unique_id "ao2udrYeBqnnW4GFfCZ33gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack