Anonymous
2026-04-22 15:21:02
(1 month ago)
Attempt to scan vulnerabilities
Hacking
Anonymous
2026-04-12 06:21:17
(1 month ago)
Attempt to scan vulnerabilities
Hacking
๐ฉ๐ช
kjaerulff
2026-03-17 15:57:12
(2 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:00:47
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-27 23:31:50
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.160 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 18:31:45.444452 2025] [security2:error] [pid 11711:tid 11711] [client 65.111.2.160:42383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dovka.com"] [uri "/.env"] [unique_id "aVBsYVAAX5hyGcQFi5p3GgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 22:05:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.160 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 17:05:47.107791 2025] [security2:error] [pid 3404307:tid 3404307] [client 65.111.2.160:53093] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sargentandco.com"] [uri "/.git/HEAD"] [unique_id "aVBYO7EDuMZ763H5fuM_PwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 21:14:56
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.160 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 16:14:53.050797 2025] [security2:error] [pid 18528:tid 18528] [client 65.111.2.160:45783] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kalvanna.com"] [uri "/.svn/wc.db"] [unique_id "aVBMTVazJJ_GQiAQda4UpwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 19:58:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.160 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 14:58:47.441099 2025] [security2:error] [pid 17384:tid 17384] [client 65.111.2.160:26823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galeriedorion.com"] [uri "/.env"] [unique_id "aVA6d5TUKh4Nz5IaFx3RLAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2025-12-27 19:05:51
(5 months ago)
trolling for resource vulnerabilities
Web App Attack
Anonymous
2025-11-14 03:22:58
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ง๐ท
hostseries
2025-10-25 05:48:20
(7 months ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2025-10-16 09:58:34
(7 months ago)
[redacted] 65.111.2.160 - - [16/Oct/2025:11:58:12 +0200] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mo ...
show more
[redacted] 65.111.2.160 - - [16/Oct/2025:11:58:12 +0200] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; rv:1.7.3) Gecko/20040913 Firefox/0.10.1"
[redacted] 65.111.2.160 - - [16/Oct/2025:11:58:16 +0200] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Linux; Android 5.1.1; HUAWEI SCL-L03 Build/HuaweiSCL-L03) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Mobile Safari/537.36"
[redacted] 65.111.2.160 - - [16/Oct/2025:11:58:17 +0200] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:39.0) Gecko/20100101 Firefox/39.0"
[redacted] 65.111.2.160 - - [16/Oct/2025:11:58:19 +0200] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Linux; Android 8.0.0; moto g(6) play) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.80 Mobile Safari/537.36"
[redacted] 65.111.2.160 - - [16/Oct/2025:11:58:21 +0200] "POST /xmlrpc.php HTTP/2
...
show less
Hacking
Web App Attack
Anonymous
2025-10-16 09:39:33
(7 months ago)
WordPress Brute Force
Brute-Force
๐ง๐ท
hostseries
2025-10-15 21:50:25
(7 months ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2025-10-14 12:59:30
(7 months ago)
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show more
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less
Brute-Force