Anonymous
2026-08-28 04:32:43
(3 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐จ๐ฆ
polycoda
2026-08-23 01:21:31
(3 weeks ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐ซ๐ท
LRob
2026-08-23 01:18:28
(3 weeks ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /.git/config
show less
Hacking
Web App Attack
Anonymous
2026-08-22 12:06:08
(4 weeks ago)
Trying to access config files
Web App Attack
๐ง๐ช
cmbplf
2026-08-22 11:42:04
(4 weeks ago)
373 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐ณ๐ฑ
DrLex0
2026-08-22 10:09:05
(4 weeks ago)
Poking for git configs using Go crap
143.244.52.53 80 - [22/Aug/2026:10:09:05 +0000] "GET /.git/con ...
show more
Poking for git configs using Go crap
143.244.52.53 80 - [22/Aug/2026:10:09:05 +0000] "GET /.git/config HTTP/1.1" 404 2383 "-" "Go-http-client/1.1"
143.244.52.53 443 - [22/Aug/2026:10:09:05 +0000] "GET /.git/config HTTP/1.1" 404 7440 "-" "Go-http-client/1.1"
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 09:17:05
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 143.244.52.53 (unn-143-244-52-53.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 143.244.52.53 (unn-143-244-52-53.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:17:01.702965 2026] [security2:error] [pid 18003:tid 18003] [client 143.244.52.53:34623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.caferutadelaseda.com"] [uri "/.git/config"] [unique_id "aolpDZtuB7-O881wL2bb3QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 08:49:05
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 143.244.52.53 (unn-143-244-52-53.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 143.244.52.53 (unn-143-244-52-53.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 04:49:01.651256 2026] [security2:error] [pid 2963:tid 2977] [client 143.244.52.53:24075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.busybeerestaurant.com"] [uri "/.git/config"] [unique_id "aolifc1UTyrQRm4TJYp4_QAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-22 05:53:58
(4 weeks ago)
cloudlinux2 fail2ban: 2026-08-22 07:48:55,658 fail2ban.filter [1480]: INFO [recidive] Fou ...
show more
cloudlinux2 fail2ban: 2026-08-22 07:48:55,658 fail2ban.filter [1480]: INFO [recidive] Found 139.5.1.37 - 2026-08-22 07:48:55cloudlinux2 fail2ban: 2026-08-22 07:48:54,942 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 139.5.1.37 - 2026-08-22 07:48:54cloudlinux2 fail2ban: 2026-08-22 07:48:55,531 fail2ban.actions [1480]: NOTICE [plesk-modsecurity] Ban 139.5.1.37cloudlinux2 fail2ban: 2026-08-22 07:49:13,911 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.68.174.31 - 2026-08-22 07:49:13cloudlinux2 fail2ban: 2026-08-22 07:49:11,187 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 146.190.75.39 - 2026-08-22 07:49:10cloudlinux2 fail2ban: 2026-08-22 07:49:13,899 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.68.174.31 - 2026-08-22 07:49:13cloudlinux2 fail2ban: 2026-08-22 07:49:10,477 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 146.190.75.39 - 2026-08-22 07:49:10cloudlinux2 fail2ban: 2026-08-22 07:4
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 05:51:28
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 143.244.52.53 (unn-143-244-52-53.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 143.244.52.53 (unn-143-244-52-53.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 01:51:23.067318 2026] [security2:error] [pid 5892:tid 5892] [client 143.244.52.53:59021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ea2cdy.es"] [uri "/.git/config"] [unique_id "aok425U7KUVWgixRe0czzwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-22 04:17:06
(4 weeks ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ฆ
URAN Publishing Service
2026-08-22 04:08:31
(4 weeks ago)
[22/Aug/2026:07:08:30 +0300] -- 143.244.52.53 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyt
2026-08-22 04:05:44
(4 weeks ago)
Sensitive File Probe
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-21 18:30:30
(4 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-08-20 20:23:55
(4 weeks ago)
[redacted] 143.244.52.53 - - [20/Aug/2026:22:23:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "M ...
show more
[redacted] 143.244.52.53 - - [20/Aug/2026:22:23:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
[redacted] 143.244.52.53 - - [20/Aug/2026:22:23:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_2_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15"
[redacted] 143.244.52.53 - - [20/Aug/2026:22:23:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Linux; Android 14; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Mobile Safari/537.36"
[redacted] 143.244.52.53 - - [20/Aug/2026:22:23:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
[redacted] 143.244.52.53 - - [20/Aug/2026:22:23:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit
...
show less
Hacking
Web App Attack