🇸🇪
OnTheEdge
2026-09-03 12:25:06
(2 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇫🇷
Sklurk
2026-07-31 00:41:35
(1 month ago)
Web App Attack
Web App Attack
🇦🇺
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
Anonymous
2026-03-22 01:40:59
(5 months ago)
Forum/form spam
Web Spam
🇩🇪
F242
2026-01-30 05:10:29
(7 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
🇦🇺
MAGIC
2026-01-14 02:02:44
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2025-12-02 21:11:56
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 16:11:48.525134 2025] [security2:error] [pid 7054:tid 7054] [client 65.111.3.212:53775] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graymatterofdc.com"] [uri "/.env"] [unique_id "aS9WFHjkHUSi8qSzIe7lWQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 07:59:22
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 02:59:17.323829 2025] [security2:error] [pid 5033:tid 5033] [client 65.111.3.212:14799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "statisticsisforwinners.com"] [uri "/.svn/wc.db"] [unique_id "aS6cVQsQdC6Qm2OJsdfpWgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 07:10:09
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 02:10:02.656233 2025] [security2:error] [pid 31225:tid 31225] [client 65.111.3.212:35705] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diveshop-pr.com"] [uri "/.env"] [unique_id "aS6QykrvKUXoIaJ79jTlggAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Swiptly
2025-12-02 05:25:55
(9 months ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 04:44:59
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:44:54.659683 2025] [security2:error] [pid 29859:tid 29859] [client 65.111.3.212:47169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intercotrading.com"] [uri "/.svn/wc.db"] [unique_id "aS5uxun91MSN10y_RiDCSwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 07:22:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:22:00.573143 2025] [security2:error] [pid 23814:tid 23814] [client 65.111.3.212:30523] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.vegasweddingvacation.com"] [uri "/.env"] [unique_id "aSQHmOC-5QnRiB-D79YxLAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 06:43:52
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:43:44.112356 2025] [security2:error] [pid 12103:tid 12137] [client 65.111.3.212:30783] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hobfl.com"] [uri "/.git/HEAD"] [unique_id "aSP-oOd3pxroRSWDTtpV7QAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 04:30:42
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:30:06.729767 2025] [security2:error] [pid 3504:tid 3504] [client 65.111.3.212:23527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kathiehazlett.com"] [uri "/.env"] [unique_id "aSPfTk9pPpGJiq-wnXWLowAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 00:50:56
(9 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack