๐บ๐ธ
TPI-Abuse
2026-01-07 19:13:02
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.12.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.12.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 14:12:57.767038 2026] [security2:error] [pid 31280:tid 31280] [client 65.111.12.34:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.click"] [uri "/.env"] [unique_id "aV6wOTeNl7Wzw1-JGjmgHgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 15:13:32
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.12.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.12.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 10:13:26.688624 2026] [security2:error] [pid 22596:tid 22596] [client 65.111.12.34:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixacast.com"] [uri "/.svn/wc.db"] [unique_id "aV54Fiob5RrobjX4RmgupQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
LTM
2025-12-29 07:20:02
(5 months ago)
WebServer - Attempts to exploit
Hacking
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2025-12-10 12:05:08
(5 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-26 11:14:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.12.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.12.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 06:14:50.694756 2025] [security2:error] [pid 11423:tid 11423] [client 65.111.12.34:38623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lakesidedigital.com"] [uri "/.git/HEAD"] [unique_id "aSbhKhG7CYlD_p7KtVgIKwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 01:11:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.12.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.12.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:11:23.498942 2025] [security2:error] [pid 3365543:tid 3365665] [client 65.111.12.34:27519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.manage.aafm.us"] [uri "/.svn/wc.db"] [unique_id "aSZTu2zJ-U6IElkF6xM3lQAAAdA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2025-11-25 21:59:02
(6 months ago)
tcp/80 (27 or more attempts)
Port Scan
๐บ๐ธ
MPL
2025-11-25 21:59:02
(6 months ago)
tcp/80 (9 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2025-11-24 05:37:02
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.12.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.12.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:36:57.996172 2025] [security2:error] [pid 985:tid 985] [client 65.111.12.34:30413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whatisozonetherapy.mroxygen.org"] [uri "/.env"] [unique_id "aSPu-ag8NWoCtfo8_1xEagAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2025-11-24 00:32:50
(6 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 65.111.12.34 (US/United States/-): ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 65.111.12.34 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2025-10-17 13:16:48
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.17 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.17 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-15 17:34:22
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-10-13 23:20:47
(7 months ago)
GlobalProtect login attempts with user jpalewi.
VPN IP
Brute-Force
Anonymous
2025-10-02 09:12:49
(8 months ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.10.02 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.10.02 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
hostseries
2025-09-30 00:32:55
(8 months ago)
Trigger: LF_DISTATTACK
Brute-Force