๐ช๐ธ
librebit
2026-05-17 05:09:24
(4 weeks ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-05-15 00:38:48
(1 month ago)
RDWeb scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-24 04:14:55
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 23 23:14:49.268134 2026] [security2:error] [pid 11588:tid 11588] [client 65.111.3.149:49879] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||primacomm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "primacomm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXRHOctG3dU_A0NFno4LKAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:07
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-25 03:59:16
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:59:11.991505 2025] [security2:error] [pid 20820:tid 20820] [client 65.111.3.149:36331] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mlundp.com"] [uri "/.env"] [unique_id "aSUpj03kKTmMZl9z5RMBjQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:24:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:24:05.619197 2025] [security2:error] [pid 21770:tid 21770] [client 65.111.3.149:36487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.shawnlayne.com"] [uri "/.git/HEAD"] [unique_id "aSUFNSpQ4KKzYI54v8rZKAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Shaik Sai Meera
2025-11-25 00:04:25
(6 months ago)
IM360 WAF: Hidden file access
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-24 09:32:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:32:12.013515 2025] [security2:error] [pid 11808:tid 11808] [client 65.111.3.149:9953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tduniverse.net"] [uri "/.git/HEAD"] [unique_id "aSQmHFQHfK4f2lSnaS0eFgAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:39:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:39:38.117996 2025] [security2:error] [pid 29447:tid 29447] [client 65.111.3.149:12437] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wellnessmassagelv.com"] [uri "/.env"] [unique_id "aSP9qhg2NKvbUogvnPXzLAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:35:50
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:35:46.286207 2025] [security2:error] [pid 6007:tid 6007] [client 65.111.3.149:52631] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.peterlundman.com"] [uri "/.env"] [unique_id "aSPuslc9UMtYX7B20kuJ2AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:24:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:24:09.151465 2025] [security2:error] [pid 14248:tid 14248] [client 65.111.3.149:38233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rktect.com"] [uri "/.git/HEAD"] [unique_id "aSPd6WB3y1YdHY_NHB3n1QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-11-19 08:51:19
(6 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2025-11-17 12:52:04
(6 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.11.17 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.11.17 is noted in report timestamp
show less
Hacking
Brute-Force
๐จ๐ฟ
lp
2025-11-17 07:21:27
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 65.111.3.149
2025-11-17T07:23:57+01:0 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 65.111.3.149
2025-11-17T07:23:57+01:00 vpn Access-Reject 'xplas22' station: 65.111.3.149 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
Anonymous
2025-11-12 20:27:39
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.11.12 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.11.12 is noted in report timestamp
show less
Hacking
Brute-Force