🇫🇷
Sklurk
2026-09-11 02:38:42
(1 day ago)
Web App Attack
Web App Attack
🇺🇸
drewf.ink
2026-08-29 16:48:12
(2 weeks ago)
[16:48] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[16:48] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
🇹🇷
neron
2026-08-12 23:06:48
(4 weeks ago)
CrowdSec blocked: http:scan detected via OPNsense firewall
Hacking
Web App Attack
🇫🇷
Sklurk
2026-08-02 03:04:01
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-08-01 01:04:48
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-31 00:01:52
(1 month ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-01-13 12:34:04
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 07:33:57.884012 2026] [security2:error] [pid 15184:tid 15184] [client 65.111.15.245:49697] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cannabizcorp.org"] [uri "/.env"] [unique_id "aWY7tXqPijpcVHoC8zROIgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
myagent.site
2026-01-13 11:55:07
(7 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
🇩🇪
Packets-Decreaser.NET
2025-12-29 14:02:13
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
🇺🇸
TPI-Abuse
2025-11-26 11:27:25
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 06:27:21.221972 2025] [security2:error] [pid 2728:tid 2728] [client 65.111.15.245:56707] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.gospectre.com"] [uri "/.env"] [unique_id "aSbkGVdxqVBD3yAlNRYcfwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 08:13:33
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:13:30.039552 2025] [security2:error] [pid 16213:tid 16213] [client 65.111.15.245:10047] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.avmcyber.com"] [uri "/.env"] [unique_id "aSa2qud3KnHN1Qz-sQctoQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 01:21:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:21:22.270961 2025] [security2:error] [pid 25989:tid 25989] [client 65.111.15.245:15001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.3wf.com"] [uri "/.svn/wc.db"] [unique_id "aSZWEpsSyWnUgaLRBn6DvQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 09:49:04
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:49:00.482358 2025] [security2:error] [pid 27384:tid 27384] [client 65.111.15.245:25233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nolaanimereviews.com"] [uri "/.git/HEAD"] [unique_id "aSQqDMngUyVB5i0_yrrk4QAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 08:14:35
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:14:26.605765 2025] [security2:error] [pid 28353:tid 28353] [client 65.111.15.245:45235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazingfittings.amazinghydraulics.com"] [uri "/.git/HEAD"] [unique_id "aSQT4jycPEORSLdHCz2HagAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-23 18:55:23
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 13:55:13.886233 2025] [security2:error] [pid 22675:tid 22675] [client 65.111.15.245:25951] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gayebrown.tulsatvmemories.com"] [uri "/.git/config"] [unique_id "aSNYkQgalQwZnYoA6q6W6wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack