🇺🇸
TPI-Abuse
2026-09-04 17:54:37
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.133.27.121 (ec2-18-133-27-121.eu-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.133.27.121 (ec2-18-133-27-121.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 13:54:30.448998 2026] [security2:error] [pid 22032:tid 22032] [client 18.133.27.121:54900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tevalaur.athome360.com"] [uri "/.git/config"] [unique_id "apsF1mEndsLItAi_HUSL4AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 23:30:03
(22 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-03 22:03:11
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-03
Web App Attack
SSH
Hacking
🇮🇹
VHosting
2026-09-03 19:40:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-03 13:42:51
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-03 11:10:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 18.133.27.121 (ec2-18-133-27-121.eu-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.133.27.121 (ec2-18-133-27-121.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:10:43.148594 2026] [security2:error] [pid 17933:tid 17933] [client 18.133.27.121:39426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.turboswim.chevronparkett.com"] [uri "/.git/config"] [unique_id "aplVsyXDO8YaYcDi1MgiJwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 08:02:25
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-03 07:46:59
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-06-24 22:45:03
(2 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
Anonymous
2026-06-24 21:49:39
(2 months ago)
18.133.27.121 - - [24/Jun/2026:16:48:36 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 ( ...
show more
18.133.27.121 - - [24/Jun/2026:16:48:36 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 185.93.230.13
18.133.27.121 - - [24/Jun/2026:16:48:37 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 185.93.230.13
18.133.27.121 - - [24/Jun/2026:16:48:37 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 185.93.230.13
18.133.27.121 - - [24/Jun/2026:16:48:38 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 185.93.230.13
18.133.27.121 - - [24/Jun/2026:16:48:38 -0500] "GET /.env.test HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintos
...
show less
Brute-Force
Bad Web Bot
Web App Attack