Anonymous
2026-09-26 20:40:23
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฌ๐ท
setupgr
2026-09-12 00:09:40
(2 weeks ago)
(wplogin_block) Blocked WP-Login Access Attempt 65.111.0.99 (US/United States/Virginia/Ashburn/-/[AS ...
show more
(wplogin_block) Blocked WP-Login Access Attempt 65.111.0.99 (US/United States/Virginia/Ashburn/-/[AS200373 3xK Tech GmbH]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 65.111.0.99 - - [12/Sep/2026:03:08:11 +0300] "POST /wp-login.php HTTP/1.1" 301 286 "https://mail.doityourself.gr/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:121.0) Gecko/20100101 Firefox/121.0"
show less
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-09-10 07:48:12
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-01 08:41:13
(4 weeks ago)
2026-09-01T18:41:12.799568+10:00 ip-172-26-1-7 wordpress(stkildashule.org.au)[222982]: XML-RPC authe ...
show more
2026-09-01T18:41:12.799568+10:00 ip-172-26-1-7 wordpress(stkildashule.org.au)[222982]: XML-RPC authentication attempt for unknown user temp3 from 65.111.0.99
...
show less
Brute-Force
Web App Attack
๐ซ๐ฎ
danskefilm.dk
2026-06-02 21:30:01
(3 months ago)
wordpress login attempts
Web App Attack
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(6 months ago)
"DDoS against public endpoint"
DDoS Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-15 22:59:33
(7 months ago)
Auto-ban: >3000 req/min op 2026-02-15
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-15 12:28:08
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.99 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 07:27:29.577582 2026] [security2:error] [pid 20076:tid 20076] [client 65.111.0.99:25009] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title34.com"] [uri "/backend/.env"] [unique_id "aZG7sZu3wtK6qMuCaR4dhgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-02-15 12:13:24
(7 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 65.111.0.99 (US/United States/-): 1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 65.111.0.99 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-02-15 04:48:33
(7 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.git/config (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .git/ found within REQUEST_FILENAME: /.git/config]
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-02-15 03:05:32
(7 months ago)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 02:15:26
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.99 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:15:20.317495 2026] [security2:error] [pid 9409:tid 9409] [client 65.111.0.99:52017] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myouenji.org"] [uri "/.git/config"] [unique_id "aZEsOK8kbUWCtiI6X2BzpAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 01:17:19
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.99 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:17:10.717931 2026] [security2:error] [pid 23389:tid 23389] [client 65.111.0.99:39697] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lyldevelopers.com"] [uri "/.env.staging"] [unique_id "aZEeltLmIrdaHnF0ANbxdgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-14 23:08:10
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.99 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 18:08:02.725671 2026] [security2:error] [pid 17809:tid 17809] [client 65.111.0.99:52103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlecreekrvranch.com"] [uri "/.env.local"] [unique_id "aZEAUoKqOiK-8w33sO1EGwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-02-14 22:47:43
(7 months ago)
Multiple WAF Violations
Web App Attack