๐บ๐ธ
NXTwoThou
2026-05-26 02:22:25
(1 week ago)
BadRequest
Web App Attack
๐ง๐ช
cmbplf
2026-03-29 04:24:56
(2 months ago)
1.000 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
Anonymous
2026-02-11 09:01:00
(3 months ago)
SMS pumping
DDoS Attack
VPN IP
Bad Web Bot
Web App Attack
Anonymous
2025-12-04 03:24:40
(6 months ago)
2025-12-04T05:24:39.343448+02:00 zanati wp(www.sahpa.co.za)[382896]: Blocked authentication attempt ...
show more
2025-12-04T05:24:39.343448+02:00 zanati wp(www.sahpa.co.za)[382896]: Blocked authentication attempt for [email protected] from 65.111.29.194
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:20:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:19:55.630783 2025] [security2:error] [pid 13517:tid 13517] [client 65.111.29.194:9633] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lindafoley.com"] [uri "/.env"] [unique_id "aSQjO-7H8tfysI5AuHT8AgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:05:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:05:36.300759 2025] [security2:error] [pid 2271:tid 2271] [client 65.111.29.194:25103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.madronabluff.com"] [uri "/.env"] [unique_id "aSP1sKklG9GLGkT-qV72VgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:11:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:11:09.887327 2025] [security2:error] [pid 9918:tid 9918] [client 65.111.29.194:52493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rookscpa.com"] [uri "/.git/HEAD"] [unique_id "aSPo7TckE4gbuvY7n-fgKgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:40:09
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:40:05.656545 2025] [security2:error] [pid 3302825:tid 3302825] [client 65.111.29.194:46057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.partnersforaccess.net"] [uri "/.svn/wc.db"] [unique_id "aSPhpR-eWpEhhpiH5OOepQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:24:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:24:03.992239 2025] [security2:error] [pid 6763:tid 6763] [client 65.111.29.194:44525] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sail.martinka.org"] [uri "/.svn/wc.db"] [unique_id "aSPd4-5iH4-PaFTfF6DbyAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-02 18:04:36
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 07:29:31
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-10 13:53:40
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 65.111.29.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 10 08:53:35.722690 2025] [security2:error] [pid 2864365:tid 2864365] [client 65.111.29.194:58065] [client 65.111.29.194] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||h-mod.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "h-mod.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z4EmX21pRVzyfjP3mHEsLQAAABk"], referer: https://h-mod.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-21 23:20:22
(1 year ago)
BruteForce IMAP/POP3
Brute-Force
Anonymous
2024-07-24 00:02:56
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-07-09 00:16:55
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH