🇺🇸
aks4226
2026-08-27 00:33:57
(2 days ago)
Abusive attempts to CONNECT via mod_proxy.
Open Proxy
🇪🇸
librebit
2026-06-23 03:46:18
(2 months ago)
Brute force
Brute-Force
🇺🇸
fbarela
2026-06-17 22:00:09
(2 months ago)
FortiGate SSL VPN login failures.
Brute-Force
Hacking
🇬🇧
consul.to
2026-02-15 12:50:57
(6 months ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
BlueWire Hosting
2026-02-15 12:49:24
(6 months ago)
Probing websites for vulnerabilities
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 11:41:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:41:34.666270 2026] [security2:error] [pid 28485:tid 28485] [client 65.111.15.149:14955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomasandross.com"] [uri "/.env.local"] [unique_id "aZGw7v6oE-mhVmD_KDgmvwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 06:08:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:08:23.394807 2026] [security2:error] [pid 11221:tid 11221] [client 65.111.15.149:13655] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sympalais.com"] [uri "/new/.git/config"] [unique_id "aZFi10rf32hlLApg0Q6wCwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 04:34:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:34:10.417499 2026] [security2:error] [pid 16879:tid 16879] [client 65.111.15.149:32877] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "studio716.info"] [uri "/backup/.git/config"] [unique_id "aZFMwpgBZn1CVZ_vVwkLMQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 03:57:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:57:03.634177 2026] [security2:error] [pid 32490:tid 32490] [client 65.111.15.149:59135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stindustries.us"] [uri "/backup/.git/config"] [unique_id "aZFED3CBCGerVrMskHFrnQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 03:22:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:22:07.176614 2026] [security2:error] [pid 9644:tid 9644] [client 65.111.15.149:49605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starthreadingsalon.com"] [uri "/admin/.env"] [unique_id "aZE737RRBc4EWueIB2j45wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-14 23:08:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 18:08:20.151645 2026] [security2:error] [pid 10035:tid 10035] [client 65.111.15.149:46147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlehorneng.com"] [uri "/admin/.env"] [unique_id "aZEAZACgts1_afP-nWYqUAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-02-14 22:59:07
(6 months ago)
Auto-ban: >3000 req/min op 2026-02-14
Hacking
Web App Attack
SSH
🇺🇸
TPI-Abuse
2026-02-14 22:37:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 17:37:24.501108 2026] [security2:error] [pid 1286:tid 1286] [client 65.111.15.149:17233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "montebiancoltd.com"] [uri "/dev/.git/config"] [unique_id "aZD5JEMB2laVRTMH1nrddgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-02-14 22:05:37
(6 months ago)
Scanning/Probing (23)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-02-14 21:59:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 16:59:08.603113 2026] [security2:error] [pid 4014:tid 4014] [client 65.111.15.149:28587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobileonlinecasinos.co"] [uri "/.env.save"] [unique_id "aZDwLNxtL5Rn0HUPpaEZIQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack