๐ช๐ธ
raiolanetworks.com
2026-09-21 04:40:49
(1 week ago)
Honeypot detection: Cisco ASA exploit attempt. 3 events observed. Reported automatically from a hone ...
show more
Honeypot detection: Cisco ASA exploit attempt. 3 events observed. Reported automatically from a honeypot sensor.
show less
Hacking
๐ฉ๐ช
Goetz
2026-09-18 09:59:43
(1 week ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
๐จ๐ฟ
lp
2026-09-04 03:21:35
(3 weeks ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 65.111.15.45
2026-09-04T04:35:18+02:0 ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 65.111.15.45
2026-09-04T04:35:18+02:00 vpn Access-Reject 'administrator' station: 65.111.15.45 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-04T04:36:57+02:00 vpn Access-Reject 'scanner' station: 65.111.15.45 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐ซ๐ท
Sklurk
2026-08-02 03:08:33
(1 month ago)
Web App Attack
Web App Attack
๐บ๐ธ
Peter Racine
2026-07-10 14:07:00
(2 months ago)
Credential stuffing - exchange accounts
Brute-Force
๐บ๐ธ
--KBXX--
2026-07-09 22:23:31
(2 months ago)
bfa, m365
Brute-Force
๐บ๐ธ
ShadowWhisperer
2026-05-10 03:32:58
(4 months ago)
DOCKER port scan / probe. GET /secrets
Port Scan
๐บ๐ธ
TPI-Abuse
2026-02-19 02:35:21
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:35:15.365490 2026] [security2:error] [pid 6629:tid 6683] [client 65.111.15.45:9843] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kd9uri.com"] [uri "/backup/.git/config"] [unique_id "aZZ246agLYHBmOgQQQTBTgAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 01:45:57
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 20:45:46.923638 2026] [security2:error] [pid 8301:tid 8301] [client 65.111.15.45:56171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karendraughon.com"] [uri "/.env.staging"] [unique_id "aZZrSvbBRdwTuZcuYxXf7wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-18 21:17:42
(7 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 18:44:01
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:43:55.678546 2026] [security2:error] [pid 14240:tid 14240] [client 65.111.15.45:50149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thisisaboutscience.com"] [uri "/backup/.git/config"] [unique_id "aZYIaydNB6n9CVVIskGvMwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 16:52:00
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 11:51:52.582910 2026] [security2:error] [pid 30307:tid 30307] [client 65.111.15.45:46897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zacharyschwartzman.com"] [uri "/admin/.env"] [unique_id "aZXuKISSbAApEIhmUUM5EwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 13:20:16
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 08:20:12.541589 2026] [security2:error] [pid 22467:tid 22485] [client 65.111.15.45:39751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "williampower.com"] [uri "/site/.git/config"] [unique_id "aZW8jI5jMpMK9RMorCuGkgAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 11:52:51
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.15.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:52:47.401041 2026] [security2:error] [pid 804532:tid 804536] [client 65.111.15.45:27713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waqm.org"] [uri "/.env.local"] [unique_id "aZWoDyVMIGSGO_bGgZA4fQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
TransAdvice-Abuse
2025-12-26 04:54:20
(9 months ago)
IRC SPAM/Flood
DDoS Attack