Anonymous
2026-04-21 14:20:25
(1 month ago)
Forum/form spam
Web Spam
๐ณ๐ฑ
Savvii
2026-03-29 19:49:08
(2 months ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-14 11:28:58
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 06:28:53.493752 2026] [security2:error] [pid 18011:tid 18011] [client 65.111.0.117:63659] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||scala-global.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "scala-global.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZBcdZ_I1hXz7dqINmOz4wAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 08:42:10
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 03:42:05.598567 2026] [security2:error] [pid 27796:tid 27796] [client 65.111.0.117:21569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fuji.cloudex.link"] [uri "/.env"] [unique_id "aWtLXY5zq4LbcWGhFtdcwgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 00:39:41
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 19:39:35.283066 2026] [security2:error] [pid 30856:tid 30856] [client 65.111.0.117:47829] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flatchestedmama.com"] [uri "/.env"] [unique_id "aWraR6ZotZ4680r8rFFSNAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 18:06:51
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 13:06:46.558874 2026] [security2:error] [pid 13612:tid 13612] [client 65.111.0.117:44213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iiiip.org"] [uri "/.env"] [unique_id "aWp-NqfW2KStMvqBRsmwhwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:55:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:55:05.305439 2025] [security2:error] [pid 4478:tid 4478] [client 65.111.0.117:30627] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cams.boens.org"] [uri "/.svn/wc.db"] [unique_id "aSQBSesBSI_DVAl0qj6_IQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:08:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:08:19.658446 2025] [security2:error] [pid 5317:tid 5317] [client 65.111.0.117:14467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.retiredinternationaltravel.com"] [uri "/.git/HEAD"] [unique_id "aSP2U703xizhF9TiZzt_BgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:07:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.117 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:07:32.767052 2025] [security2:error] [pid 10999:tid 10999] [client 65.111.0.117:40749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.totenclaus.es"] [uri "/.svn/wc.db"] [unique_id "aSPoFMRzPDJfuE8b5THUZAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-02 13:43:54
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 07:35:18
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐จ๐ฆ
wil.com
2025-10-16 18:32:01
(7 months ago)
GlobalProtect login attempts with user dontez.
VPN IP
Brute-Force
Anonymous
2025-10-15 14:24:59
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.15 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.15 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-15 13:09:14
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-08 02:03:27
(7 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.08 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.08 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-07 19:54:24
(7 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.07 is noted in report timestamp
show less
Hacking
Brute-Force