๐ซ๐ท
ELYAZ
2026-06-16 05:26:06
(15 hours ago)
(y4) Failed scan -byebye- from 65.111.27.233 (TH/Thailand/-): (CF_ENABLE)
Hacking
๐ฉ๐ช
georgengelmann
2026-06-15 18:22:08
(1 day ago)
Failed login attempt for admin
Brute-Force
Web App Attack
๐ฆ๐บ
MAGIC
2025-12-24 00:06:12
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-25 04:45:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:45:14.221763 2025] [security2:error] [pid 1817001:tid 1817045] [client 65.111.27.233:28527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.anglicancommission.com"] [uri "/.git/HEAD"] [unique_id "aSU0WmR1ttxeyDpsCa9dfwAAAYY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:08:34
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:08:28.550104 2025] [security2:error] [pid 771209:tid 771209] [client 65.111.27.233:9503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.carmichaellaw.org"] [uri "/.env"] [unique_id "aSUrvFJ6U5vhSHu2YJk4eAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:31:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:31:44.450088 2025] [security2:error] [pid 31848:tid 31848] [client 65.111.27.233:50495] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.otrantocapital.com"] [uri "/.svn/wc.db"] [unique_id "aSUHAIOdUYXf9ZFUXLHDKAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:58:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:58:12.583047 2025] [security2:error] [pid 28577:tid 28577] [client 65.111.27.233:57051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nexthop.com"] [uri "/.git/HEAD"] [unique_id "aSQeJENQb2RCYTUUy_hr-gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-24 08:17:42
(6 months ago)
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:41:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:41:38.902674 2025] [security2:error] [pid 5102:tid 5118] [client 65.111.27.233:26251] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bakmail.net"] [uri "/.git/HEAD"] [unique_id "aSQMMiR4b9K7bCaDrEc2VAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:55:41
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:55:37.187765 2025] [security2:error] [pid 27083:tid 27083] [client 65.111.27.233:54423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bsa1688.com"] [uri "/.git/HEAD"] [unique_id "aSQBaeIHfDLsLoFQZ45QaAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:41:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:41:47.249993 2025] [security2:error] [pid 29440:tid 29440] [client 65.111.27.233:56943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rogerg.com"] [uri "/.git/HEAD"] [unique_id "aSPwG71G7vbUvoB4WXurvwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:13:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:13:02.948046 2025] [security2:error] [pid 19608:tid 19608] [client 65.111.27.233:27737] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sabbathseminars.net"] [uri "/.env"] [unique_id "aSPpXveq4KTvsbRJkuyeYwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:39:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:39:37.344779 2025] [security2:error] [pid 31235:tid 31235] [client 65.111.27.233:22755] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sawmat.com"] [uri "/.env"] [unique_id "aSPhiZCR5fHZxt-YDxvx_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-19 08:39:49
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 65.111.27.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 19 04:39:43.758251 2025] [security2:error] [pid 2938:tid 2938] [client 65.111.27.233:15711] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goalsnet.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goalsnet.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aPSjzxh74f9jM8YErhWHPgAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
SOC [GOLINE SA]
2025-01-16 19:00:50
(1 year ago)
FortiGate detected brute force login from IP 65.111.27.233
Brute-Force