🇨🇭
backslash
2026-09-08 05:48:02
(4 hours ago)
block ruleset 51D5331ECDCF70C2C6410C0D0EEB5F69B17B5F56
Bad Web Bot
🇸🇪
OnTheEdge
2026-09-03 10:18:21
(5 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇺🇸
drewf.ink
2026-09-01 20:17:52
(6 days ago)
[20:17] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[20:17] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
🇫🇷
Sklurk
2026-07-07 17:26:35
(2 months ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-02-12 02:46:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 21:46:19.743428 2026] [security2:error] [pid 1171731:tid 1171731] [client 65.111.14.93:44593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsndetx.com"] [uri "/backup/.git/config"] [unique_id "aY0--2-8rZZo6Hm_hiLq_gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-11 00:12:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 19:12:02.094838 2026] [security2:error] [pid 1113:tid 1113] [client 65.111.14.93:40585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aprilparks.com"] [uri "/v2/.git/config"] [unique_id "aYvJUlKLb4qIF8F0UIhB9gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-02-10 23:00:32
(6 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
🇺🇸
TPI-Abuse
2026-02-10 06:16:53
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 01:16:45.148937 2026] [security2:error] [pid 20028:tid 20028] [client 65.111.14.93:36555] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ik3co.com"] [uri "/backup/.git/config"] [unique_id "aYrNTcTzdajWlx_cFFZMnAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-10 04:58:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 23:58:04.961839 2026] [security2:error] [pid 2774307:tid 2774307] [client 65.111.14.93:38049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idetailingcreatives.com"] [uri "/.env.local"] [unique_id "aYq63LqgOtliRG9Tl4Cl0wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-10 03:04:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:04:40.296497 2026] [security2:error] [pid 11546:tid 11546] [client 65.111.14.93:50639] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madrigalscripts.com"] [uri "/site/.git/config"] [unique_id "aYqgSIUcQ2N-EgJ6dhuQaQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-10 02:15:41
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:15:37.141396 2026] [security2:error] [pid 1036081:tid 1036170] [client 65.111.14.93:46807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killasgarage.bike"] [uri "/api/.env"] [unique_id "aYqUyc__7REXY7sHL-BiEgAAAcc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-10 00:37:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:37:26.491632 2026] [security2:error] [pid 7700:tid 7700] [client 65.111.14.93:30705] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kevintheadventurer.org"] [uri "/frontend/.env"] [unique_id "aYp9xkWitbDEbfqwTof4wgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 23:33:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:33:31.234126 2026] [security2:error] [pid 12746:tid 12789] [client 65.111.14.93:14843] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kellenlee.com"] [uri "/.env.staging"] [unique_id "aYpuyy7qoT-4nEbOWPXdzQAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-09 22:43:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:43:54.777675 2026] [security2:error] [pid 1389:tid 1389] [client 65.111.14.93:43733] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "houston-church-of-god.org"] [uri "/frontend/.env"] [unique_id "aYpjKpyLI-3jLuWrnL455gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
myagent.site
2026-02-09 22:05:31
(6 months ago)
Blocking for trying to access an exploit file: /api/.env
Hacking