๐ฟ๐ฆ
conure
2026-07-27 18:25:29
(17 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 17:18:07
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 63.179.242.72 (ec2-63-179-242-72.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.179.242.72 (ec2-63-179-242-72.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 13:18:02.290161 2026] [security2:error] [pid 4075116:tid 4075116] [client 63.179.242.72:35004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modalguitarist.com"] [uri "/.git/config"] [unique_id "ameSylsugv8ruEE7aWO2KgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-27 16:33:57
(19 hours ago)
cloudlinux2 fail2ban: 2026-07-27 18:29:19,283 fail2ban.actions [1917]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-27 18:29:19,283 fail2ban.actions [1917]: NOTICE [plesk-modsecurity] Ban 223.223.133.244cloudlinux2 fail2ban: 2026-07-27 18:29:19,189 fail2ban.filter [1917]: INFO [plesk-modsecurity] Found 223.223.133.244 - 2026-07-27 18:29:19cloudlinux2 fail2ban: 2026-07-27 18:29:19,578 fail2ban.filter [1917]: INFO [recidive] Found 223.223.133.244 - 2026-07-27 18:29:19cloudlinux2 fail2ban: 2026-07-27 18:30:01,995 fail2ban.filter [1917]: INFO [plesk-modsecurity] Found 63.179.242.72 - 2026-07-27 18:30:01cloudlinux2 fail2ban: 2026-07-27 18:29:59,256 fail2ban.filter [1917]: INFO [plesk-modsecurity] Found 63.179.242.72 - 2026-07-27 18:29:59cloudlinux2 fail2ban: 2026-07-27 18:30:01,982 fail2ban.filter [1917]: INFO [plesk-modsecurity] Found 63.179.242.72 - 2026-07-27 18:30:01cloudlinux2 fail2ban: 2026-07-27 18:30:01,971 fail2ban.filter [1917]: INFO [plesk-modsecurity] Found 63.179.242.72 - 2026-07-27 18:30:01cloudlinux2 fail2ban:
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 12:27:13
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 63.179.242.72 (ec2-63-179-242-72.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.179.242.72 (ec2-63-179-242-72.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:27:06.207114 2026] [security2:error] [pid 1131554:tid 1131554] [client 63.179.242.72:40344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobresearchinc.com"] [uri "/.git/config"] [unique_id "amdOmvd5bVZFtkCRnPRxyQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-07-27 11:38:44
(23 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ฆ๐บ
rubixstudios
2026-07-27 08:08:02
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 07:56:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 63.179.242.72 (ec2-63-179-242-72.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.179.242.72 (ec2-63-179-242-72.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:56:39.483346 2026] [security2:error] [pid 3077104:tid 3077104] [client 63.179.242.72:57336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobiletitleclerk.com"] [uri "/.git/config"] [unique_id "amcPN-G78z2ujv_ZIMQs_AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 06:43:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 63.179.242.72 (ec2-63-179-242-72.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.179.242.72 (ec2-63-179-242-72.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:43:20.410491 2026] [security2:error] [pid 56950:tid 56950] [client 63.179.242.72:53620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobileonlinecasinos.co"] [uri "/.git/config"] [unique_id "amb-CLSQ8Q1F1Sh38bHlmAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-26 21:59:59
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-26
Web App Attack
SSH
Hacking
๐ฏ๐ต
weils.net
2026-07-26 02:52:50
(2 days ago)
2026-07-26 10:52:49(GMT+8) - /cms/.env
Bad Web Bot
๐ฉ๐ช
yitzhaq
2026-07-26 02:41:10
(2 days ago)
63.179.242.72 - - [26/Jul/2026:04:41:09 +0200] "GET /phpinfo HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Win ...
show more
63.179.242.72 - - [26/Jul/2026:04:41:09 +0200] "GET /phpinfo HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.179.242.72 - - [26/Jul/2026:04:41:09 +0200] "GET /staging/phpinfo.php HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.179.242.72 - - [26/Jul/2026:04:41:09 +0200] "GET /beta/phpinfo.php HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.179.242.72 - - [26/Jul/2026:04:41:09 +0200] "GET /uat/phpinfo.php HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.179.242.72 - - [26/Jul/2026:04:41:09 +0200] "GET /admin/phpinfo.php HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/1
show less
Web App Attack
Hacking
๐ฉ๐ช
Blexyel
2026-07-26 02:35:58
(2 days ago)
63.179.242.72 - - [26/Jul/2026:04:35:57 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
63.179.242.72 - - [26/Jul/2026:04:35:57 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
debaba
2026-07-26 02:13:53
(2 days ago)
[26/Jul/2026:02:13:53.572111 +0000] amVtYWMnNMaO4i3uxBDpJgAAAA0 63.179.242.72 33592 127.0.0.1 7081
[ ...
show more
[26/Jul/2026:02:13:53.572111 +0000] amVtYWMnNMaO4i3uxBDpJgAAAA0 63.179.242.72 33592 127.0.0.1 7081
[26/Jul/2026:02:13:53.648138 +0000] amVtYSiquE5RARF
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-07-26 02:07:01
(2 days ago)
Web vulnerability probing: /.env.staging
Web App Attack
๐ฉ๐ช
Hazzard
2026-07-26 02:05:50
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection