๐ซ๐ท
Sklurk
2026-06-20 02:46:04
(1 day ago)
Web App Attack
Web App Attack
Anonymous
2026-06-11 08:25:22
(1 week ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-26 12:12:47
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ฑ๐ป
garmtech.com
2026-01-17 11:46:32
(5 months ago)
IM360 WAF: WordPress plugin/theme auto install block
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:02:08
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-26 06:39:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:39:01.451532 2025] [security2:error] [pid 16933:tid 16959] [client 65.111.23.253:11479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.philacentric.com"] [uri "/.svn/wc.db"] [unique_id "aSaghW__nRv550N5ZrlG0gAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 06:03:28
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:03:25.315431 2025] [security2:error] [pid 5892:tid 5892] [client 65.111.23.253:56505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nube.vientodelevante.es"] [uri "/.git/HEAD"] [unique_id "aSaYLZDj8CDXujISz6p5qwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:55:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:55:36.643627 2025] [security2:error] [pid 23521:tid 23521] [client 65.111.23.253:18643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.littlehornengineering.com"] [uri "/.git/HEAD"] [unique_id "aSVS6Ezw8cM4zm9fAKd10gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:52:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:52:48.275619 2025] [security2:error] [pid 28889:tid 28889] [client 65.111.23.253:20795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cpking.com"] [uri "/.git/HEAD"] [unique_id "aSU2ICEZ-j6jhHCqk1HCmQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:03:53
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:03:46.063959 2025] [security2:error] [pid 23835:tid 23835] [client 65.111.23.253:48549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.esslinger.us"] [uri "/.env"] [unique_id "aSUqosaA31Dw80AX4APGrwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:10:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:10:03.308086 2025] [security2:error] [pid 1647141:tid 1647205] [client 65.111.23.253:43165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tobiume-shounika.com"] [uri "/.git/HEAD"] [unique_id "aSUP-9ffCdpZ5cNrCNdkgQAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:05:33
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:05:10.097026 2025] [security2:error] [pid 29154:tid 29154] [client 65.111.23.253:38859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stickittomebuttons.com"] [uri "/.git/HEAD"] [unique_id "aSTytknwXpBoXIC7VB_SFgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
barbarella
2025-11-24 17:53:20
(6 months ago)
illegal scan for AWS credentials file (GET /.aws/credentials)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 08:53:11
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 03:53:08.563998 2025] [security2:error] [pid 16513:tid 16513] [client 65.111.23.253:18065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thesunvegan.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aQ8E9DBzOoTOqSaAe-gwbQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-04 22:22:08
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 65.111.23.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 04 17:22:04.024978 2025] [security2:error] [pid 1083233:tid 1083233] [client 65.111.23.253:56959] [client 65.111.23.253] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nekstlevel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nekstlevel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z6KTDNyI5WckBgojsX5MNQAAAA8"], referer: https://nekstlevel.com
show less
Brute-Force
Bad Web Bot
Web App Attack