๐จ๐ฆ
Kacelly Nima
2026-09-21 01:15:42
(43 minutes ago)
Bad Web Bot
Blog Spam
Brute-Force
DDoS Attack
DNS Compromise
DNS Poisoning
Email Spam
Exploited Host
Fraud Orders
Fraud VoIP
FTP Brute-Force
Hacking
IoT Targeted
Open Proxy
Phishing
Ping of Death
Port Scan
Spoofing
SQL Injection
SSH
VPN IP
Web App Attack
Web Spam
๐ธ๐ช
shab
2026-09-04 02:20:44
(2 weeks ago)
Suspicious VPN activity
Brute-Force
๐จ๐ญ
SOC [GOLINE SA]
2026-09-02 16:31:25
(2 weeks ago)
[RoutePulse | 2026-09-02T16:31:24Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 65.111.3.13 ...
show more
[RoutePulse | 2026-09-02T16:31:24Z | RTBH-INJECTED]
ATTACK CLASS: vpn_bruteforce
SOURCE: 65.111.3.139
EVIDENCE: Cisco VPN RA Brute force on Cisco FTDv โ distributed attack (6 attempts/15min)
DETECTION: Conviction Engine SPRT + 14-detector ML stack (6-model weighted ensemble) + 5-pillar threat scoring
ACTION: BGP null route injected at RoutePulse network edge
show less
Brute-Force
Hacking
๐ซ๐ท
Sklurk
2026-09-01 00:47:15
(2 weeks ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 04:24:01
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 23:23:53.882888 2026] [security2:error] [pid 7950:tid 7950] [client 65.111.3.139:18203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kln.ne.jp"] [uri "/.env"] [unique_id "aZaQWVG2MRuwE2QmoMlKOQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 03:44:44
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:44:41.135104 2026] [security2:error] [pid 26388:tid 26388] [client 65.111.3.139:51919] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinaffanchufoods.com"] [uri "/app/.git/config"] [unique_id "aZaHKVqOA0zPgyPtWbmu1gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 03:18:20
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:18:14.701274 2026] [security2:error] [pid 32744:tid 32744] [client 65.111.3.139:55023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kewlkarz.com"] [uri "/api/.git/config"] [unique_id "aZaA9oawDmPj9M0bkppenQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 02:33:27
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 21:33:18.744693 2026] [security2:error] [pid 31174:tid 31174] [client 65.111.3.139:15705] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kcmastercleaners.com"] [uri "/app/.git/config"] [unique_id "aZZ2biYzvFIB3NcvWQeTggAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 00:10:52
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 19:10:46.421362 2026] [security2:error] [pid 32199:tid 32199] [client 65.111.3.139:49327] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitality-webb.com"] [uri "/app/.git/config"] [unique_id "aZZVBi5A6CZZqZdNxMGQIgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 19:09:20
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 14:09:15.840440 2026] [security2:error] [pid 23651:tid 23651] [client 65.111.3.139:10027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "timlandry.com"] [uri "/v2/.git/config"] [unique_id "aZYOW_q1TCmvnqJr46fbwwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-02-18 13:49:12
(7 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 11:44:54
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:44:46.983252 2026] [security2:error] [pid 20929:tid 20929] [client 65.111.3.139:51849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wallpaperpro.com"] [uri "/new/.git/config"] [unique_id "aZWmLsWMSn8663CPPBVkqwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-22 17:38:16
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
fbarela
2025-11-07 22:01:16
(10 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2025-11-02 17:21:37
(10 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 07:29:44
Port Scan
Brute-Force
Exploited Host
Web App Attack