|
π«π·
Sklurk
|
|
Web App Attack
|
Web App Attack
|
|
|
π«π·
Sklurk
|
|
Web App Attack
|
Web App Attack
|
|
|
π«π·
Sklurk
|
|
Web App Attack
|
Web App Attack
|
|
|
Anonymous
|
|
Apache probe; attempts=18; exact paths: /xmlrpc.php
|
Web App Attack
|
|
|
π©πͺ
stinpriza
|
|
Web App Attack
|
Web App Attack
|
|
|
π©πͺ
stinpriza
|
|
Web App Attack
|
Web App Attack
|
|
|
π«π·
geot
|
|
GET http://<<removed>>.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1
|
Port Scan
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:50:20.933858 2025] [security2:error] [pid 3486:tid 3486] [client 65.111.27.149:49237] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ola.jbaydeliveries.com"] [uri "/.svn/wc.db"] [unique_id "aSa_TMOmVJ2YUYfqLvP5ywAAAA4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π§πͺ
sid3windr
|
|
GET /.env (Tarpitted for 2m10s, wasted 7.73kB)
|
Web App Attack
|
|
|
Anonymous
|
|
suspicious request in access.log
|
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:11:22.541736 2025] [security2:error] [pid 21166:tid 21166] [client 65.111.27.149:28741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.4ehardware.4ehardware.com"] [uri "/.env"] [unique_id "aSVIis7uWf7TQFt035tKNwAAAAY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:42:22.751959 2025] [security2:error] [pid 32735:tid 309] [client 65.111.27.149:44929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreammile.info"] [uri "/.git/HEAD"] [unique_id "aSUzruyRrmvyed2G3rXM8AAAAEg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:53:49.343454 2025] [security2:error] [pid 10068:tid 10068] [client 65.111.27.149:31279] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davedoeswater.com"] [uri "/.git/HEAD"] [unique_id "aSUaPR7aHfu5l4cAcDSwvwAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:34:26.167469 2025] [security2:error] [pid 243932:tid 243971] [client 65.111.27.149:24349] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.acornway.com"] [uri "/.svn/wc.db"] [unique_id "aSQmolc8EtVRkmyAMev0RQAAAQY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:51:23.386912 2025] [security2:error] [pid 12864:tid 12864] [client 65.111.27.149:51381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.therustedtree.com"] [uri "/.env"] [unique_id "aSQci0E5ANObw9F3cJZbjwAAAAg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|