๐ฉ๐ช
FeG Deutschland
2026-06-25 10:17:06
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
raph
2026-06-22 07:46:08
(4 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 07:58:22
(1 week ago)
Web attack blocked by Wordfence on mergel.nu (1 hit). Reported by CRMON.
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-12 08:07:08
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-06-11 14:39:13
(2 weeks ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -39.885 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -39.885 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Sa
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
Carsten
2026-05-30 11:54:53
(3 weeks ago)
bad web bot
Port Scan
Anonymous
2026-05-01 20:10:25
(1 month ago)
Forum/form spam
Web Spam
๐ฉ๐ช
LRob.fr
2026-03-27 10:45:04
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-12-24 03:20:33
(6 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2025-12-02 20:39:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.105 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 15:39:29.747591 2025] [security2:error] [pid 1977:tid 1977] [client 65.111.0.105:15545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "limeroc.com"] [uri "/.git/HEAD"] [unique_id "aS9OgXYlRjGBOkWqhcOKJwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 19:53:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.105 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 14:52:55.763779 2025] [security2:error] [pid 10259:tid 10259] [client 65.111.0.105:57815] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alhashim.com"] [uri "/.git/HEAD"] [unique_id "aS9DlxOrrbJaeSYFvyZ7tAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 07:54:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.105 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 02:54:26.682165 2025] [security2:error] [pid 1196:tid 1196] [client 65.111.0.105:12385] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haerringer.com"] [uri "/.env"] [unique_id "aS6bMmtBBTqh7CKzFu-b6AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 00:47:20
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-31 21:38:29
(7 months ago)
[redacted] 65.111.0.105 - - [31/Oct/2025:22:37:53 +0100] "POST /xmlrpc.php HTTP/2.0" 200 426 "-" "Mo ...
show more
[redacted] 65.111.0.105 - - [31/Oct/2025:22:37:53 +0100] "POST /xmlrpc.php HTTP/2.0" 200 426 "-" "Mozilla/5.0 (iPad; U; CPU OS 3_2_2 like Mac OS X; en-us) AppleWebKit/531.21.10 (KHTML, like Gecko) Version/4.0.4 Mobile/7B500 Safari/531.21.10"
[redacted] 65.111.0.105 - - [31/Oct/2025:22:37:54 +0100] "POST /xmlrpc.php HTTP/2.0" 200 426 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; Touch; rv:11.0) like Gecko"
[redacted] 65.111.0.105 - - [31/Oct/2025:22:38:03 +0100] "POST /xmlrpc.php HTTP/2.0" 200 426 "-" "Mozilla/5.0 (Windows NT 6.1; rv:17.0) Gecko/20100101 Firefox/20.6.14"
[redacted] 65.111.0.105 - - [31/Oct/2025:22:38:05 +0100] "POST /xmlrpc.php HTTP/2.0" 200 426 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 10_2_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/23.1.148956103 Mobile/14D27 Safari/600.1.4"
[redacted] 65.111.0.105 - - [31/Oct/2025:22:38:05 +0100] "POST /xmlrpc.php HTTP/2.0" 200 426
...
show less
Hacking
Web App Attack
Anonymous
2025-10-30 14:27:48
(7 months ago)
WordPress Brute Force
Brute-Force