๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐ช๐ธ
10dencehispahard SL
2025-12-29 09:35:44
(5 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ฎ๐น
VHosting
2025-12-24 03:46:07
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐บ๐ธ
octageeks.com
2025-11-27 05:10:54
(6 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 01:03:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.11.219 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.11.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:03:34.040348 2025] [security2:error] [pid 12136:tid 12136] [client 65.111.11.219:50531] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rdu.us"] [uri "/.env"] [unique_id "aSZR5qCivXJkxK3EBKn8VAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-25 23:24:38
(6 months ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:29:35
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.11.219 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.11.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:29:27.285752 2025] [security2:error] [pid 13767:tid 13767] [client 65.111.11.219:55899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.triplecrownfundraising.com"] [uri "/.env"] [unique_id "aSP7RzJrE5qCTY6MYvyO-gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 00:34:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.11.219 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.11.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 19:17:10.318072 2025] [security2:error] [pid 9153:tid 9153] [client 65.111.11.219:31191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.monogrampartynapkins.com"] [uri "/.git/HEAD"] [unique_id "aSOkBhD6oEU7iYwu5NJrwgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 01:50:23
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 65.111.11.219 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 65.111.11.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 20:50:18.475007 2025] [security2:error] [pid 29829:tid 29835] [client 65.111.11.219:55175] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.xxxmain.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.xxxmain.com"] [uri "/s3cmd.ini"] [unique_id "aRU5WoJQ-haOHPpGOhSePwAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
hostseries
2025-10-25 06:19:53
(7 months ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2025-10-18 09:25:07
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.18 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-17 04:43:04
(7 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.17 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.17 is noted in report timestamp
show less
Hacking
Brute-Force
๐จ๐ฆ
wil.com
2025-10-16 11:09:56
(7 months ago)
GlobalProtect login attempts with user ahaggard.
VPN IP
Brute-Force
Anonymous
2025-10-15 20:41:48
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.15 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.15 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-14 07:41:26
(7 months ago)
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show more
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less
Brute-Force