Anonymous
2026-06-04 16:26:30
(3 days ago)
104.207.63.248 - - [04/Jun/2026:16:26:30 +0000] "GET http://curio.codes/.env HTTP/1.1" 301 570 "-" " ...
show more
104.207.63.248 - - [04/Jun/2026:16:26:30 +0000] "GET http://curio.codes/.env HTTP/1.1" 301 570 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Edg/119.0.0.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-01 14:06:47
(6 days ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 05:08:54
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 00:08:50.327527 2026] [security2:error] [pid 8477:tid 8477] [client 104.207.63.248:49663] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kozyramodularhomebuilder.com"] [uri "/.env"] [unique_id "aZaa4vHH5sJXtBPCYNcOBAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 03:41:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:41:15.807213 2026] [security2:error] [pid 26505:tid 26505] [client 104.207.63.248:27893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kim-porter.com"] [uri "/admin/.git/config"] [unique_id "aZaGWzVxg2Goj5IJANKqRgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-19 03:05:20
(3 months ago)
Too many Status 40X (12)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 02:58:23
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:58:17.564699 2026] [security2:error] [pid 12238:tid 12238] [client 104.207.63.248:61575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ken-parker.com"] [uri "/v2/.git/config"] [unique_id "aZZ8SeJ3vO5BSmgJBTsEAgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 02:10:23
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:10:18.894886 2026] [security2:error] [pid 22351:tid 22351] [client 104.207.63.248:26381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "katharinanitzpon.com"] [uri "/dev/.git/config"] [unique_id "aZZxClgtjTNlTgbI-yGQKgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 00:17:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 19:17:29.931724 2026] [security2:error] [pid 1827:tid 1827] [client 104.207.63.248:38237] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vjrott.com"] [uri "/backup/.git/config"] [unique_id "aZZWmQqsDb7fZN0NW9cOvAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-02-18 23:17:56
(3 months ago)
http-sensitive-files - IP: 104.207.63.248 - time="2026-02-19T00:17:56+01:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 104.207.63.248 - time="2026-02-19T00:17:56+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 104.207.63.248 (FR/200373) : 4h ban on Ip 104.207.63.248" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 22:59:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 17:59:52.187032 2026] [security2:error] [pid 22581:tid 22581] [client 104.207.63.248:46297] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vc1.com"] [uri "/frontend/.env"] [unique_id "aZZEaObDIKjtq9XPSkfYcQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 20:16:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 15:16:26.121498 2026] [security2:error] [pid 31140:tid 31140] [client 104.207.63.248:46741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trasimeno.ws"] [uri "/.env"] [unique_id "aZYeGkrPy838pNWWCvK6owAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 11:53:20
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:53:13.418169 2026] [security2:error] [pid 1181725:tid 1181725] [client 104.207.63.248:12529] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wardellbrown.com"] [uri "/admin/.git/config"] [unique_id "aZWoKVj1OlyC-kC7uKjs6AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-12-24 01:05:14
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2025-11-25 07:33:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.63.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:33:31.635408 2025] [security2:error] [pid 27221:tid 27221] [client 104.207.63.248:33389] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ficklepassionproductions.com"] [uri "/.git/HEAD"] [unique_id "aSVby9AJ4pbN50fV6gO5nAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack