๐บ๐ธ
lostswordfish.com
2026-09-14 16:38:03
(1 day ago)
Wordfence waf block on parsol
Web App Attack
Anonymous
2026-09-03 21:13:49
(1 week ago)
2026-09-03T23:13:49.183978+02:00 polaris wp(bikeschool.co.za)[1037613]: Authentication attempt for u ...
show more
2026-09-03T23:13:49.183978+02:00 polaris wp(bikeschool.co.za)[1037613]: Authentication attempt for unknown user Nx_admin from 65.111.27.81
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
spamverify.com
2026-09-01 19:31:12
(2 weeks ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
ctidrv
2026-09-01 11:54:22
(2 weeks ago)
Honeypot detection. Threat score: 90/100. Collector: wp_login. | Request: POST /wp-login.php | Crede ...
show more
Honeypot detection. Threat score: 90/100. Collector: wp_login. | Request: POST /wp-login.php | Credentials captured: user=root | UA: Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 | rDNS: 65.111.27.81 | Reasons: wp_login_probe, wp_credentials_submitted, common_wp_username
show less
Brute-Force
Bad Web Bot
๐ฆ๐บ
screwlooseit.com.au
2026-07-08 12:28:16
(2 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
US/United States/-
Web App Attack
๐จ๐ญ
backslash
2026-07-05 19:03:14
(2 months ago)
block ruleset 51D5331ECDCF70C2C6410C0D0EEB5F69B17B5F56
Bad Web Bot
๐ซ๐ฎ
inlink.ltd
2026-05-25 10:32:08
(3 months ago)
Known malicious PHP file or CMS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 07:43:20
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 02:43:14.884576 2026] [security2:error] [pid 20598:tid 20598] [client 65.111.27.81:55839] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.qcyprus.com"] [uri "/.env"] [unique_id "aWs9kj2lfZW4CPRw0v24FQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 05:49:36
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 00:49:29.706142 2026] [security2:error] [pid 15616:tid 15616] [client 65.111.27.81:21685] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.petcareconfessions.com"] [uri "/.env"] [unique_id "aWsi6cIb-b_ssvNKL0y_ZAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2026-01-13 01:42:47
(8 months ago)
Form spam
Web Spam
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:11
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-27 22:59:33
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 17:59:26.554555 2025] [security2:error] [pid 22665:tid 22665] [client 65.111.27.81:59145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toddgoranson.com"] [uri "/.env"] [unique_id "aVBkzqS1vaYjhu7C0IGJWQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-27 19:48:18
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 14:48:12.249014 2025] [security2:error] [pid 6307:tid 6307] [client 65.111.27.81:48223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waxjet510.com"] [uri "/.git/HEAD"] [unique_id "aVA3_JA9m6uvD9NPvlIm9wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
etu brutus
2025-12-27 17:41:29
(8 months ago)
65.111.27.81 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 04:13:29
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.27.81 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.27.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 23:13:23.096373 2025] [security2:error] [pid 18614:tid 18614] [client 65.111.27.81:12391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "otcraftworks.com"] [uri "/.env"] [unique_id "aTeh4zeBEWsnKwKU0nHIvQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack