π©πͺ
Goetz
2026-08-31 05:13:57
(9 hours ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2026-08-04 00:08:12
(3 weeks ago)
65.111.27.46 - - [04/Aug/2026:00:08:11 +0000] "GET /wp-login.php HTTP/1.1" 404 50942 "-" "Mozilla/5. ...
show more
65.111.27.46 - - [04/Aug/2026:00:08:11 +0000] "GET /wp-login.php HTTP/1.1" 404 50942 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π«π·
Sklurk
2026-08-03 02:57:42
(4 weeks ago)
Web App Attack
Web App Attack
π«π·
Sklurk
2026-07-09 00:33:07
(1 month ago)
Web App Attack
Web App Attack
π«π·
ELYAZ
2026-06-24 06:34:32
(2 months ago)
(y4) Failed scan -byebye- from 65.111.27.46 (TH/Thailand/-): (CF_ENABLE)
Hacking
π¦πΊ
paulshipley.com.au
2026-06-22 23:05:57
(2 months ago)
[Tue Jun 23 09:05:56.478416 2026] [security2:error] [pid 175781] [client 65.111.27.46:36841] [client ...
show more
[Tue Jun 23 09:05:56.478416 2026] [security2:error] [pid 175781] [client 65.111.27.46:36841] [client 65.111.27.46] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/xmlrpc.php"] [unique_id "ajm_1MDEI5eu2SQx_IiQPgAAAAk"]
...
show less
Web App Attack
π«π·
Sklurk
2026-06-20 03:51:45
(2 months ago)
Web App Attack
Web App Attack
π«π·
Tilellit.PRO
2026-06-16 02:21:59
(2 months ago)
Fail2Ban banned 65.111.27.46 for security violations in jail wp-armour. Log: 2026/06/16 02:21:58 [er ...
show more
Fail2Ban banned 65.111.27.46 for security violations in jail wp-armour. Log: 2026/06/16 02:21:58 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 65.111.27.46 | Target: wplogin" , client: 65.111.27.46, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
πͺπΈ
loadsoporte
2026-01-02 02:53:38
(7 months ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
πΊπΈ
TPI-Abuse
2025-12-29 05:51:29
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:51:23.461313 2025] [security2:error] [pid 18976:tid 18976] [client 65.111.27.46:27609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icwcruisersguide.com"] [uri "/.git/HEAD"] [unique_id "aVIW27SYXV4mcnzD0zevsAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-29 05:12:23
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:12:16.027946 2025] [security2:error] [pid 31828:tid 31828] [client 65.111.27.46:25133] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jvcsat.com"] [uri "/.git/HEAD"] [unique_id "aVINsNxef7girfuWQugcLAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
jjnxpct
2025-11-26 04:56:08
(9 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.git/HEAD (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .git/ found within REQUEST_FILENAME: /.git/HEAD]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 04:24:50
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:24:25.506261 2025] [security2:error] [pid 789317:tid 789317] [client 65.111.27.46:35655] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.1214productions.com"] [uri "/.git/HEAD"] [unique_id "aSUveRJN8Zc_Xku4i0S-MgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 04:04:36
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:04:29.609186 2025] [security2:error] [pid 27022:tid 27022] [client 65.111.27.46:28825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.enespiral.net"] [uri "/.svn/wc.db"] [unique_id "aSUqzYi7RlIiWqacExUcNQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 02:58:53
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:58:41.912251 2025] [security2:error] [pid 24411:tid 24411] [client 65.111.27.46:13681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.exhaustthelimits.org"] [uri "/.env"] [unique_id "aSUbYRWxLtTzxTwjTZD7BQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack