πΊπΈ
mnsf
2026-02-19 22:05:14
(3 months ago)
Scanning/Probing (23)
Brute-Force
Web App Attack
π¬π§
Aetherweb Ark
2026-02-19 04:06:01
(3 months ago)
(mod_security) mod_security (id:949110) triggered by 65.111.22.72 (GB/United Kingdom/-): N in the la ...
show more
(mod_security) mod_security (id:949110) triggered by 65.111.22.72 (GB/United Kingdom/-): N in the last X secs
show less
Web App Attack
π©πͺ
Mario Silber
2026-02-19 03:49:45
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted] 65.111.22.72 (GB/United Kingdom/-)
SQL Injection
πΊπΈ
TPI-Abuse
2026-02-19 03:14:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:14:00.299675 2026] [security2:error] [pid 16642:tid 16660] [client 65.111.22.72:11099] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.net"] [uri "/backup/.git/config"] [unique_id "aZZ_-HacsSfoPZBQxAMIJgAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-19 02:10:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:10:46.172157 2026] [security2:error] [pid 2746139:tid 2746139] [client 65.111.22.72:17499] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathiekate.com"] [uri "/api/.env"] [unique_id "aZZxJmK0YUCdH2uo_RVHUwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-02-19 01:55:37
(3 months ago)
Probing websites for vulnerabilities
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-19 00:19:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 19:19:32.020219 2026] [security2:error] [pid 15233:tid 15233] [client 65.111.22.72:27701] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vmmailing.com"] [uri "/backup/.git/config"] [unique_id "aZZXFCXjDIAy2tq_1UOmnAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-02-18 21:05:24
(3 months ago)
Too many Status 40X (12)
Scanning/Probing (14)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-18 20:05:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 15:05:23.955746 2026] [security2:error] [pid 28342:tid 28342] [client 65.111.22.72:40631] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tractiondrive.com"] [uri "/app/.git/config"] [unique_id "aZYbgwLC_ddwbI8ZfIjhNAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-18 18:46:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:46:49.424318 2026] [security2:error] [pid 28077:tid 28077] [client 65.111.22.72:32319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thommesen.net"] [uri "/backend/.env"] [unique_id "aZYJGXcKzDtE_9GgkQ6a1gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-18 12:20:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:20:47.669747 2026] [security2:error] [pid 8923:tid 8923] [client 65.111.22.72:25667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weavergroup.us"] [uri "/api/.env"] [unique_id "aZWun1wq-bFm4vcdIw_JnwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-18 12:00:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.22.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:00:52.848775 2026] [security2:error] [pid 19259:tid 19259] [client 65.111.22.72:26145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wastetrack.io"] [uri "/config/.env"] [unique_id "aZWp9MAEWseOAkFS_1jDFQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-02-18 11:47:32
(3 months ago)
Try to access /admin/.env
Web App Attack
π³π±
homeshowdomain.nl
2026-02-10 23:00:11
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
πΊπΈ
ambor
2026-02-10 05:25:02
(3 months ago)
Honeypot triggered: /backup/.git/config on ifebridge.com. User-Agent: Mozilla/5.0 (Windows NT 10.0; ...
show more
Honeypot triggered: /backup/.git/config on ifebridge.com. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36. Method: GET
show less
Web App Attack