๐ฌ๐ง
spamverify.com
2026-06-03 15:19:12
(2 days ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-05-31 09:25:22
(5 days ago)
(y4) Failed scan -byebye- from 65.111.12.83 (US/United States/-): (CF_ENABLE)
Hacking
๐ซ๐ท
pm33
2026-05-25 23:05:14
(1 week ago)
Wordpress login attempts
Brute-Force
๐ฉ๐ช
iNetWorker
2026-05-25 22:38:44
(1 week ago)
trolling for resource vulnerabilities
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-12 22:02:29
(3 weeks ago)
Auto-ban: >3000 req/min op 2026-05-12
Web App Attack
SSH
Hacking
๐ฌ๐ง
PeravixGroup
2026-05-07 11:51:08
(4 weeks ago)
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Sever ...
show more
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐ฉ๐ช
4server
2026-05-04 00:39:04
(1 month ago)
[MonMay0402:39:00.3821442026][security2:error][pid3693929:tid3694029][client65.111.12.83:0]ModSecuri ...
show more
[MonMay0402:39:00.3821442026][security2:error][pid3693929:tid3694029][client65.111.12.83:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.atelier-lara.ch\"][uri\"/.aws/credentials\"][unique_id\"affqpFTWj3ltXdPh7ABA7gAAAMc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-04-30 07:34:36
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-04-30 01:45:02
(1 month ago)
suspicious request in access.log
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-04-28 02:39:49
(1 month ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 65.111.12.83 - - [28/Apr/2026:03 ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 65.111.12.83 - - [28/Apr/2026:03:39:47 +0100] GET /s3cmd.ini HTTP/1.1 403 3108 - Mozilla/5.0 (Linux; Android 8.0.0; LLD-L31) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.90 Mobile Safari/537.36
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 01:35:09
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 65.111.12.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 65.111.12.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 21:35:00.855379 2026] [security2:error] [pid 3861:tid 3861] [client 65.111.12.83:24367] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jpfamilyllc.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jpfamilyllc.com"] [uri "/s3cmd.ini"] [unique_id "afAOxLrKZUWxo2BX07DvxQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-12 05:40:14
(1 month ago)
Attempt to scan vulnerabilities
Hacking
๐ณ๐ฑ
jjnxpct
2026-03-29 03:48:36
(2 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /dagopeningen (Rule ID: 942540) - SQL Authentication bypass (split query) [Suspicious: '; found within ARGS:return: ';]
show less
Web App Attack
SQL Injection
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-24 05:53:35
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.12.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.12.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:53:27.847283 2025] [security2:error] [pid 5343:tid 5343] [client 65.111.12.83:21431] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "akronpartybuses.com"] [uri "/.git/HEAD"] [unique_id "aSPy10U7SUFLQP6XoGLLGgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:37:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.12.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.12.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:37:19.278044 2025] [security2:error] [pid 32001:tid 32001] [client 65.111.12.83:41801] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aguitas.com"] [uri "/.svn/wc.db"] [unique_id "aSPvD_OMt2R48oK9q34tpAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack