🇭🇺
bcsaba
2026-08-30 12:27:14
(8 hours ago)
Going for WP CVE-2026-63030
65.111.15.134 - - [30/Aug/2026:14:27:11 +0200] "POST /?rest_route=/batch ...
show more
Going for WP CVE-2026-63030
65.111.15.134 - - [30/Aug/2026:14:27:11 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 403 146 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:153.0) Gecko/20100101 Firefox/153.0"
show less
Web App Attack
🇩🇪
Goetz
2026-08-27 12:29:41
(3 days ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
🇫🇷
Sklurk
2026-08-02 03:34:18
(4 weeks ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-08-01 02:15:09
(4 weeks ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-31 02:02:01
(4 weeks ago)
Web App Attack
Web App Attack
🇦🇺
MAGIC
2026-03-25 01:29:53
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2026-03-24 02:09:32
(5 months ago)
Forum/form spam
Web Spam
🇦🇺
MAGIC
2026-02-26 00:37:00
(6 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇺🇸
mnsf
2026-02-16 02:05:57
(6 months ago)
Scanning/Probing (27)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 11:27:41
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:27:38.010471 2026] [security2:error] [pid 31169:tid 31169] [client 65.111.15.134:12215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oxygenfarm.com"] [uri "/.env"] [unique_id "aZGtqr7a0_qRfNBHdHYwEQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 11:11:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:10:54.634549 2026] [security2:error] [pid 9986:tid 9986] [client 65.111.15.134:57299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ourcritterguy.com"] [uri "/dev/.git/config"] [unique_id "aZGpvh3OPAm2VjD7pgcs6QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-15 07:05:07
(6 months ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 05:45:27
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:45:21.287790 2026] [security2:error] [pid 22261:tid 22261] [client 65.111.15.134:56269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scarylogcabin.com"] [uri "/api/.env"] [unique_id "aZFdcWFfF1Tf1korttlK7wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 04:26:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:26:19.472854 2026] [security2:error] [pid 18700:tid 18700] [client 65.111.15.134:35671] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "praiseworthy.info"] [uri "/v2/.git/config"] [unique_id "aZFK6wGOrA-wQY1xEp86_wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 03:43:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:43:24.919394 2026] [security2:error] [pid 26110:tid 26110] [client 65.111.15.134:51429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noreservationslocations.com"] [uri "/.env.staging"] [unique_id "aZFA3D7EvTzVm50JvrgHiAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack