๐ง๐ฌ
HighWay
2026-07-27 17:40:53
(1 day ago)
63.186.250.70 - - [27/Jul/2026:17:40:51 +0000] "GET /.git/config HTTP/1.1" 404 607 "-" "Mozilla/5.0 ...
show more
63.186.250.70 - - [27/Jul/2026:17:40:51 +0000] "GET /.git/config HTTP/1.1" 404 607 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.186.250.70 - - [27/Jul/2026:17:40:51 +0000] "GET /.env HTTP/1.1" 404 607 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
63.186.250.70 - - [27/Jul/2026:17:40:51 +0000] "GET /.env.local HTTP/1.1" 404 607 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ReyhZhao
2026-07-27 15:55:55
(1 day ago)
Multiple ModSecurity blocks detected from a single source IP, including a restricted file access att ...
show more
Multiple ModSecurity blocks detected from a single source IP, including a restricted file access attempt and disallowed request content types.
show less
Brute-Force
๐ณ๐ฑ
Mangelot Hosting
2026-07-27 15:10:31
(1 day ago)
(modsecurity) srv103 ModSecurity 63.186.250.70 (DE/Germany/ec2-63-186-250-70.eu-central-1.compute.am ...
show more
(modsecurity) srv103 ModSecurity 63.186.250.70 (DE/Germany/ec2-63-186-250-70.eu-central-1.compute.amazonaws.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:25:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 63.186.250.70 (ec2-63-186-250-70.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.186.250.70 (ec2-63-186-250-70.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:25:35.817649 2026] [security2:error] [pid 54323:tid 54323] [client 63.186.250.70:44072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.unwaved.com"] [uri "/.git/config"] [unique_id "amckD2eYFdhnI33qD9SndAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 09:19:42
(1 day ago)
(caddyscan) Scanner path probe from 63.186.250.70 (DE/Germany/ec2-63-186-250-70.eu-central-1.compute ...
show more
(caddyscan) Scanner path probe from 63.186.250.70 (DE/Germany/ec2-63-186-250-70.eu-central-1.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 63.186.250.70 - - [27/Jul/2026:09:19:41 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 63.186.250.70 - - [27/Jul/2026:09:19:41 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 63.186.250.70 - - [27/Jul/2026:09:19:42 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 63.186.250.70 - - [27/Jul/2026:09:19:42 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 63.186.250.70 - - [27/Jul/2026:09:19:42 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐ท๐บ
DZBOT
2026-07-27 05:36:31
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-26 08:23:12
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 63.186.250.70 (DE/Germany/ec2-63-18 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 63.186.250.70 (DE/Germany/ec2-63-186-250-70.eu-central-1.compute.amazonaws.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-07-25 22:47:43
(3 days ago)
GET /scripts/.env HTTP/1.1
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 22:03:20
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-24.
show less
Web App Attack
SSH
Hacking
๐ฑ๐ป
garmtech.com
2026-07-25 05:33:13
(3 days ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:02:37
(4 days ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 12:04:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 63.186.250.70 (ec2-63-186-250-70.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.186.250.70 (ec2-63-186-250-70.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:04:03.705844 2026] [security2:error] [pid 691604:tid 691683] [client 63.186.250.70:56640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neutrahouse1939.ward-bergerhouse.org"] [uri "/.git/config"] [unique_id "amNUs-1wfD0uO57YwVOZ2QAAAZg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 11:22:28
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 63.186.250.70 (ec2-63-186-250-70.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.186.250.70 (ec2-63-186-250-70.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:22:24.739373 2026] [security2:error] [pid 3799036:tid 3799036] [client 63.186.250.70:39508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neuromancer.xyz"] [uri "/.git/config"] [unique_id "amNK8DQ_Z1TqnRK1X7HzhgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:21:21
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 63.186.250.70 (ec2-63-186-250-70.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.186.250.70 (ec2-63-186-250-70.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:21:13.645238 2026] [security2:error] [pid 3800187:tid 3800187] [client 63.186.250.70:54708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "networkteam.csennews.com"] [uri "/.git/config"] [unique_id "amMuiVJFlxpQU0yK2IJlQgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:00:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 63.186.250.70 (ec2-63-186-250-70.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 63.186.250.70 (ec2-63-186-250-70.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:00:13.652019 2026] [security2:error] [pid 1229460:tid 1229460] [client 63.186.250.70:56040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "network22.net"] [uri "/.git/config"] [unique_id "amMpnWGEPxwLSgqdHW83aAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack