๐บ๐ธ
TPI-Abuse
2026-07-27 20:47:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 16:47:45.687988 2026] [security2:error] [pid 3500516:tid 3500540] [client 63.33.202.7:40302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.totalbodycare753.kylight.com"] [uri "/.git/config"] [unique_id "amfD8e9uWUziumFn5q8cwwAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-07-27 18:17:54
(1 day ago)
Web App Attack Exploid from 63.33.202.7
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 18:07:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:06:54.493489 2026] [security2:error] [pid 2508191:tid 2508229] [client 63.33.202.7:39506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.torreymanagement.com.torreydc.com"] [uri "/.git/config"] [unique_id "ameePidcY0zvcazLVjypPgAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-27 17:41:15
(1 day ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 14:26:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:26:22.927035 2026] [security2:error] [pid 21132:tid 21132] [client 63.33.202.7:50266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.torahorah.royal-barbershop.com"] [uri "/.git/config"] [unique_id "amdqjviihg1MZiNaX-TanAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-07-27 11:40:10
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 08:15:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 04:15:12.331533 2026] [security2:error] [pid 1467806:tid 1467806] [client 63.33.202.7:47836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.topfer.toepfer.org"] [uri "/.git/config"] [unique_id "amcTkF-_-wPNP7ZZT3S3gAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 05:21:35
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
hidemail.app
2026-07-27 04:45:52
(1 day ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-26 10:52:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 06:52:20.212773 2026] [security2:error] [pid 1860485:tid 1860485] [client 63.33.202.7:40498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tracklocross.com.mrcd.org"] [uri "/.git/config"] [unique_id "amXm5HZQo-vPdT0mCMsqtwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-26 10:08:58
(2 days ago)
cloudlinux2 fail2ban: 2026-07-26 12:04:08,029 fail2ban.filter [1888]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-26 12:04:08,029 fail2ban.filter [1888]: INFO [plesk-modsecurity] Found 63.33.202.7 - 2026-07-26 12:04:08cloudlinux2 fail2ban: 2026-07-26 12:04:08,161 fail2ban.filter [1888]: INFO [plesk-modsecurity] Found 63.33.202.7 - 2026-07-26 12:04:08cloudlinux2 fail2ban: 2026-07-26 12:04:07,869 fail2ban.filter [1888]: INFO [plesk-modsecurity] Found 63.33.202.7 - 2026-07-26 12:04:07cloudlinux2 fail2ban: 2026-07-26 12:04:08,095 fail2ban.filter [1888]: INFO [plesk-modsecurity] Found 63.33.202.7 - 2026-07-26 12:04:08cloudlinux2 fail2ban: 2026-07-26 12:04:08,171 fail2ban.filter [1888]: INFO [recidive] Found 63.33.202.7 - 2026-07-26 12:04:08cloudlinux2 fail2ban: 2026-07-26 12:04:08,133 fail2ban.filter [1888]: INFO [plesk-modsecurity] Found 63.33.202.7 - 2026-07-26 12:04:08cloudlinux2 fail2ban: 2026-07-26 12:04:07,965 fail2ban.filter [1888]: INFO [plesk-modsecurity] Found 63.33.202.7 - 2026-07-26 12:04:07cloudlinux2 fail2b
show less
FTP Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-26 06:42:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 63.33.202.7 (ec2-63-33-202-7.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 02:42:39.036173 2026] [security2:error] [pid 1650442:tid 1650442] [client 63.33.202.7:40760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.toxicwater.helpkccare.org"] [uri "/.git/config"] [unique_id "amWsX5BHN_-js7P4FMzXBQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-25 06:55:37
(3 days ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-07-25 06:53:57
(3 days ago)
[da.kdns.gr] httpd-config-scan: sites=www.tires-zografou.gr; logs=/var/log/httpd/domains/tires-zogra ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.tires-zografou.gr; logs=/var/log/httpd/domains/tires-zografou.gr.log; samples=/staging/.env | /opt/.env | /laravel/.env
show less
Hacking
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-25 06:41:15
(3 days ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/redis/.env
Web App Attack