🇫🇷
Sklurk
2026-09-06 00:34:33
(1 hour ago)
Web App Attack
Web App Attack
🇨🇿
Countryman
2026-09-04 00:10:01
(2 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇩🇪
Bedios GmbH
2026-09-03 15:25:50
(2 days ago)
Wordpress hacking attempt
Web App Attack
🇨🇭
backslash
2026-04-15 19:18:02
(4 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇩🇪
ger-stg-sifi1
2026-01-02 22:33:07
(8 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇳🇱
GabrielJST
2025-12-18 01:17:15
(8 months ago)
*Port Scan* detected from 65.111.21.131 (BR/Brazil/-).
Port Scan
🇺🇸
TPI-Abuse
2025-11-27 22:54:10
(9 months ago)
(mod_security) mod_security (id:210740) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210740) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 17:54:03.742766 2025] [security2:error] [pid 712083:tid 712083] [client 65.111.21.131:46161] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||www.neff.family.name|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "www.neff.family.name"] [uri "/unwiki/default.asp"] [unique_id "aSjWi6Vic-59iRZGqOMZ1QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 10:59:22
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 05:59:16.842079 2025] [security2:error] [pid 9542:tid 9553] [client 65.111.21.131:39931] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.joshuapaulweckesser.com"] [uri "/.env"] [unique_id "aSbdhI3KfyUJoLcCWK2XVgAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 06:29:25
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:29:20.487647 2025] [security2:error] [pid 25114:tid 25114] [client 65.111.21.131:43459] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ratalads.com"] [uri "/.env"] [unique_id "aSaeQC2BsTPbEp3xXr8c-gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 03:04:32
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 22:04:28.835506 2025] [security2:error] [pid 18538:tid 18538] [client 65.111.21.131:33851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.toys-alliance.com"] [uri "/.svn/wc.db"] [unique_id "aSZuPO3dkl-hIZ4sLMwRXAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 06:56:06
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:55:59.256721 2025] [security2:error] [pid 25710:tid 25710] [client 65.111.21.131:14583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.paulshorrock.com"] [uri "/.git/HEAD"] [unique_id "aSVS_9Z59WMagsYoiSiRtQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 02:17:09
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:17:05.291029 2025] [security2:error] [pid 8121:tid 8121] [client 65.111.21.131:52911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "csme-eprr.com"] [uri "/.git/HEAD"] [unique_id "aSURofFzPTkRu-VtVQ7FfQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2025-11-24 22:24:11
(9 months ago)
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 08:08:51
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.21.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:08:22.555237 2025] [security2:error] [pid 26957:tid 26957] [client 65.111.21.131:22387] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.vplow.com"] [uri "/.git/HEAD"] [unique_id "aSQSdnkfMWz-yjQu-bjszQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
relianoid.com
2025-11-16 18:16:28
(9 months ago)
POST Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web Spam