๐ซ๐ท
mail.avx.gr
2026-07-27 15:40:37
(4 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 44.251.226.177 - - [24/Jul/2026:10:06:48 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 44.251.226.177 - - [24/Jul/2026:10:06:48 +0300] "GET /.git/config HTTP/1.1" 403 6224 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 11:34:18
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:34:11.737631 2026] [security2:error] [pid 24350:tid 24350] [client 44.251.226.177:58176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fixmywellwater.com"] [uri "/.git/config"] [unique_id "amdCM6Ws65XeSU-x8xSJ-gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 11:01:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:01:35.269875 2026] [security2:error] [pid 4149899:tid 4149899] [client 44.251.226.177:43442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fixitsmart.com"] [uri "/.git/config"] [unique_id "amc6jwWxiEqgdcOOE31zVQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:22:03
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:21:55.926393 2026] [security2:error] [pid 2319511:tid 2319520] [client 44.251.226.177:58418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fix4life.com"] [uri "/.git/config"] [unique_id "amcjM6GnUyEBsl0dVXIKAgAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 07:36:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:36:04.053011 2026] [security2:error] [pid 3286595:tid 3286595] [client 44.251.226.177:50164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fivestardrives.truefauxstudio.com"] [uri "/.git/config"] [unique_id "amcKZOBKCPKPPO_CBcYlIAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
smithoo4
2026-07-27 07:03:58
(4 days ago)
2026-07-27T03:03:56.680484-04:00 fiveohm nginx[3227]: 2026/07/27 03:03:56 [error] 3227#3227: *1362 l ...
show more
2026-07-27T03:03:56.680484-04:00 fiveohm nginx[3227]: 2026/07/27 03:03:56 [error] 3227#3227: *1362 limiting requests, excess: 20.090 by zone "general", client: 44.251.226.177, server: fiveohm.duckdns.org, request: "GET /staging/.env HTTP/1.1", host: "fiveohm.duckdns.org"
2026-07-27T03:03:56.966865-04:00 fiveohm nginx[3227]: 2026/07/27 03:03:56 [error] 3227#3227: *1362 limiting requests, excess: 20.220 by zone "general", client: 44.251.226.177, server: fiveohm.duckdns.org, request: "GET /wordpress/.env HTTP/1.1", host: "fiveohm.duckdns.org"
2026-07-27T03:03:57.181717-04:00 fiveohm nginx[3227]: 2026/07/27 03:03:57 [error] 3227#3227: *1362 limiting requests, excess: 20.070 by zone "general", client: 44.251.226.177, server: fiveohm.duckdns.org, request: "GET /drupal/.env HTTP/1.1", host: "fiveohm.duckdns.org"
2026-07-27T03:03:57.467664-04:00 fiveohm nginx[3227]: 2026/07/27 03:03:57 [error] 3227#3227: *1362 limiting requests, excess: 20.210 by zone "general", client: 44.251.226.177, server:
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-27 07:02:39
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:02:34.933678 2026] [security2:error] [pid 78467:tid 78467] [client 44.251.226.177:44596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fiveoceansconsulting.com"] [uri "/.git/config"] [unique_id "amcCikRAGaRjvQSAleStEAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:47:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:47:50.232940 2026] [security2:error] [pid 3437789:tid 3437789] [client 44.251.226.177:43438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "five21.com"] [uri "/.git/config"] [unique_id "ambxBmzAIXSVnPCplgpafAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 04:53:32
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:53:25.588567 2026] [security2:error] [pid 2874860:tid 2874860] [client 44.251.226.177:54632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fitzcosound.com"] [uri "/.git/config"] [unique_id "ambkReix_zAK9198uGhPMAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-26 05:06:21
(5 days ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (41/60 min)'; Requests=41
Port Scan
๐ซ๐ท
mail.avx.gr
2026-07-24 07:06:49
(1 week ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 44.251.226.177 - - [24/Jul/2026:10:06:48 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 44.251.226.177 - - [24/Jul/2026:10:06:48 +0300] "GET /.git/config HTTP/1.1" 403 6224 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-24 06:53:57
(1 week ago)
cloudlinux2 fail2ban: 2026-07-24 08:50:02,239 fail2ban.filter [1816]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-24 08:50:02,239 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 44.251.226.177 - 2026-07-24 08:50:02cloudlinux2 fail2ban: 2026-07-24 08:50:02,924 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 44.251.226.177 - 2026-07-24 08:50:02cloudlinux2 fail2ban: 2026-07-24 08:50:02,575 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 44.251.226.177 - 2026-07-24 08:50:02cloudlinux2 fail2ban: 2026-07-24 08:50:03,099 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 44.251.226.177 - 2026-07-24 08:50:03cloudlinux2 fail2ban: 2026-07-24 08:50:03,355 fail2ban.filter [1816]: INFO [recidive] Found 44.251.226.177 - 2026-07-24 08:50:03cloudlinux2 fail2ban: 2026-07-24 08:50:03,349 fail2ban.actions [1816]: NOTICE [plesk-modsecurity] Ban 44.251.226.177cloudlinux2 fail2ban: 2026-07-24 08:50:03,474 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 44.251.226.177 - 2026-07-24 08:50:03cloudlinux2 fail2ban:
show less
Web App Attack
๐จ๐ญ
4server
2026-07-24 06:45:31
(1 week ago)
[FriJul2408:45:25.7253852026][security2:error][pid2269448:tid2270035][client44.251.226.177:0]ModSecu ...
show more
[FriJul2408:45:25.7253852026][security2:error][pid2269448:tid2270035][client44.251.226.177:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"avvnicolaurbani.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"amMKBdMuM2HieC2CWynnggAAAFM\"]
show less
Hacking
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-24 06:41:14
(1 week ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 05:45:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 44.251.226.177 (ec2-44-251-226-177.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:45:26.616078 2026] [security2:error] [pid 3906372:tid 3906372] [client 44.251.226.177:41852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avrknives.com"] [uri "/.git/config"] [unique_id "amL79q_vQPKJyIjON5y2WwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack