๐บ๐ธ
TPI-Abuse
2026-07-25 04:33:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 63.177.61.217 (ec2-63-177-61-217.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.177.61.217 (ec2-63-177-61-217.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 00:33:36.345519 2026] [security2:error] [pid 1089564:tid 1089564] [client 63.177.61.217:54300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pushthemarketing.com"] [uri "/.git/config"] [unique_id "amQ8oLdkIXFgsCyPywKcoAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-07-25 04:04:40
(1 day ago)
(modsecurity) srv102 ModSecurity 63.177.61.217 (DE/Germany/ec2-63-177-61-217.eu-central-1.compute.am ...
show more
(modsecurity) srv102 ModSecurity 63.177.61.217 (DE/Germany/ec2-63-177-61-217.eu-central-1.compute.amazonaws.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ช๐ธ
alferez
2026-07-25 04:03:25
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-25 00:22:11
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 13:27:36
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 12:00:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 63.177.61.217 (ec2-63-177-61-217.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.177.61.217 (ec2-63-177-61-217.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:00:50.293812 2026] [security2:error] [pid 1476366:tid 1476366] [client 63.177.61.217:58032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nwuoregon.org"] [uri "/.git/config"] [unique_id "amNT8hFPzBnrU6dQbANYyAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-24 10:27:34
(2 days ago)
63.177.61.217 - - [24/Jul/2026:13:27:31 +0300] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 ...
show more
63.177.61.217 - - [24/Jul/2026:13:27:31 +0300] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.177.61.217 - - [24/Jul/2026:13:27:32 +0300] "GET /.env HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:54:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 63.177.61.217 (ec2-63-177-61-217.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.177.61.217 (ec2-63-177-61-217.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:54:56.031925 2026] [security2:error] [pid 3926857:tid 3926857] [client 63.177.61.217:48372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nvafc.com"] [uri "/.git/config"] [unique_id "amM2cJ1cMf51N4iWrlsR8wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-07-24 08:25:02
(2 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-07-24 06:23:41
(2 days ago)
63.177.61.217 - - [24/Jul/2026:08:23:39 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintos ...
show more
63.177.61.217 - - [24/Jul/2026:08:23:39 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.177.61.217 - - [24/Jul/2026:08:23:39 +0200] "POST / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.177.61.217 - - [24/Jul/2026:08:23:40 +0200] "POST / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.177.61.217 - - [24/Jul/2026:08:23:40 +0200] "POST / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.177.61.217 - - [24/Jul/2026:08:23:40 +0200] "GET /.git/config HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 05:15:04
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-24 05:13:56
(2 days ago)
cloudlinux2 fail2ban: 2026-07-24 07:09:34,720 fail2ban.filter [1816]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-24 07:09:34,720 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 152.59.151.27 - 2026-07-24 07:09:34cloudlinux2 fail2ban: 2026-07-24 07:09:34,743 fail2ban.filter [1816]: INFO [recidive] Found 152.59.151.27 - 2026-07-24 07:09:34cloudlinux2 fail2ban: 2026-07-24 07:09:34,737 fail2ban.actions [1816]: NOTICE [plesk-modsecurity] Ban 152.59.151.27cloudlinux2 fail2ban: 2026-07-24 07:09:36,376 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 103.149.16.51 - 2026-07-24 07:09:36cloudlinux2 fail2ban: 2026-07-24 07:09:36,751 fail2ban.actions [1816]: NOTICE [plesk-modsecurity] Ban 103.149.16.51cloudlinux2 fail2ban: 2026-07-24 07:09:36,758 fail2ban.filter [1816]: INFO [recidive] Found 103.149.16.51 - 2026-07-24 07:09:36cloudlinux2 fail2ban: 2026-07-24 07:09:47,608 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 63.177.61.217 - 2026-07-24 07:09:47cloudlinux2 fail2ban: 2026-07-24 07:09:47,652 fail2ban.filter
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-24 03:08:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 63.177.61.217 (ec2-63-177-61-217.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.177.61.217 (ec2-63-177-61-217.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 23:08:42.264935 2026] [security2:error] [pid 195920:tid 195920] [client 63.177.61.217:46182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nuevo.allcostaricarentals.com"] [uri "/.git/config"] [unique_id "amLXOsIXNa_w8OJKFOmqEAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack