๐บ๐ธ
Ben Schoolland
2026-09-19 13:24:16
(1 hour ago)
Requested known WordPress backdoor/scanner-only paths. No legitimate use.
Bad Web Bot
Web App Attack
๐บ๐ธ
Ben Schoolland
2026-09-11 11:09:11
(1 week ago)
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legiti ...
show more
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legitimate use.
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-09-09 03:43:24
(1 week ago)
Web App Attack
Web App Attack
๐ฉ๐ช
Goetz
2026-09-03 09:39:55
(2 weeks ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-08-22 22:50:19
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ท
ELYAZ
2026-08-22 22:09:06
(3 weeks ago)
(wordpress) Failed wordpress login from 65.111.29.65 (FR/France/-): (CF_ENABLE)
Brute-Force
๐จ๐ฆ
DRI
2026-08-22 05:40:31
(4 weeks ago)
Web attack/Malicious activity detected
Web App Attack
๐ฒ๐น
Malta
2026-08-21 21:06:52
(4 weeks ago)
65.111.29.65 - - [21/Aug/2026:23:06:52 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; I ...
show more
65.111.29.65 - - [21/Aug/2026:23:06:52 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15"
show less
Hacking
Web App Attack
VPN IP
๐ฉ๐ช
4server
2026-05-25 07:55:50
(3 months ago)
[MonMay2509:55:46.8902022026][security2:error][pid3780779:tid3780900][client65.111.29.65:0]ModSecuri ...
show more
[MonMay2509:55:46.8902022026][security2:error][pid3780779:tid3780900][client65.111.29.65:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"www.eimeko.ch\"][uri\"/xmlrpc.php\"][unique_id\"ahQAgiLS7UXElq9WQzKs5wAAAQo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
myagent.site
2026-03-27 00:04:22
(5 months ago)
Blocking for trying to access an exploit file: /v2/.git/config
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-13 06:28:10
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.29.65 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.29.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 01:28:07.651480 2026] [security2:error] [pid 25451:tid 25451] [client 65.111.29.65:36821] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kraftre.com"] [uri "/.env.staging"] [unique_id "aY7Ed7HBqoSRiB-1CKr9kgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 05:43:24
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.29.65 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.29.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 00:43:20.044516 2026] [security2:error] [pid 17438:tid 17438] [client 65.111.29.65:57177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kokr.org"] [uri "/frontend/.env"] [unique_id "aY65-Jg5LOsnZCtTc_4-uQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 05:10:28
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.29.65 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.29.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 00:10:22.560803 2026] [security2:error] [pid 2583:tid 2583] [client 65.111.29.65:42075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kmg365media.com"] [uri "/admin/.env"] [unique_id "aY6yPlz2XQEfy4UnKrL_cwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 02:32:00
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.29.65 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.29.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 21:31:52.502238 2026] [security2:error] [pid 14675:tid 14675] [client 65.111.29.65:23503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kemela.com"] [uri "/frontend/.env"] [unique_id "aY6NGOiCtYbDcojAGEt8jQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-13 02:02:26
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.29.65 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.29.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 21:02:23.084211 2026] [security2:error] [pid 2108:tid 2108] [client 65.111.29.65:49023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kccares.help"] [uri "/.git/config"] [unique_id "aY6GL7-CcTaELXTMU0t2ogAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack