Anonymous
2026-05-25 16:34:28
(1 week ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ณ๐ฑ
homeshowdomain.nl
2026-05-23 21:59:42
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-22.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-05-22 22:02:02
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-05-22
Web App Attack
SSH
Hacking
๐ฉ๐ช
FeG Deutschland
2026-05-22 19:39:10
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ง๐ช
cmbplf
2026-05-22 18:43:18
(2 weeks ago)
7.253 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-22 17:37:40
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 13:37:33.710603 2026] [security2:error] [pid 31296:tid 31296] [client 8.231.99.162:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pixacast.com"] [uri "/.git/config"] [unique_id "ahCUXS0QwFQ5jgLpPxwYYwAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 16:22:27
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 12:22:20.918880 2026] [security2:error] [pid 32464:tid 32464] [client 8.231.99.162:50632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.visitcampbellford.modeltdr.com"] [uri "/.git/config"] [unique_id "ahCCvJj_yncNaGGfldYanAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 15:39:19
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 11:39:14.089161 2026] [security2:error] [pid 32310:tid 32310] [client 8.231.99.162:43826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.giganticmediallc.com"] [uri "/.git/config"] [unique_id "ahB4oiI3_PnrN3XEGFOEwwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 13:51:21
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 09:51:14.046326 2026] [security2:error] [pid 17052:tid 17052] [client 8.231.99.162:55246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "langkawi-boat-registration.com"] [uri "/.git/config"] [unique_id "ahBfUkeTffWqHJPpPkU0iQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 10:34:00
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 06:33:55.084759 2026] [security2:error] [pid 13585:tid 13585] [client 8.231.99.162:42414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.parkhan.com"] [uri "/.git/config"] [unique_id "ahAxEwLldHLQ-N-hNHVcCQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 08:39:51
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.99.162 (162.99.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 04:39:45.752451 2026] [security2:error] [pid 7848:tid 7848] [client 8.231.99.162:45560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.paulburns.com"] [uri "/.git/config"] [unique_id "ahAWUeUBMzzWtvrqVaBboAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-22 03:54:23
(2 weeks ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.231.99.162 (IN/India/162.99.231.8.b ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.231.99.162 (IN/India/162.99.231.8.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ณ๐ฑ
ParaBug
2026-05-19 22:40:52
(2 weeks ago)
8.231.99.162 - - [20/May/2026:00:40:51 +0200] "\x16\x03\x01\x05\xde\x01" 400 432 "-" "-"
...
Phishing
Brute-Force
Web App Attack