|
π«π·
Sklurk
|
|
Web App Attack
|
Web App Attack
|
|
|
π¨π
backslash
|
|
|
Bad Web Bot
|
|
|
πͺπΈ
librebit
|
|
Brute force
|
Brute-Force
|
|
|
π¦πΊ
RedBear IT
|
|
"DDoS against public endpoint"
|
DDoS Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 65.111.3.235 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 65.111.3.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 18:06:35.300822 2026] [security2:error] [pid 8789:tid 8789] [client 65.111.3.235:62205] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||keysenterprise.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "keysenterprise.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZjo-_NA7k941R6IeV9iXAAAAAk"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
mind5t0rm
|
|
(WPLOGIN) WP Login Attack 65.111.3.235 (US/United States/-): 3 in the last 3600 secs; Ports: *; Dire ...
show more
(WPLOGIN) WP Login Attack 65.111.3.235 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 65.111.3.235 - - [21/Feb/2026:03:58:24 +0700] "GET /wp-login.php HTTP/2.0" 200 2349 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
65.111.3.235 - - [21/Feb/2026:03:58:29 +0700] "POST /wp-login.php HTTP/2.0" 200 2498 "https://convercon.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
65.111.3.235 - - [21/Feb/2026:03:58:34 +0700] "GET /wp-login.php?redirect_to=https%3A%2F%2Fconvercon.com%2Fwp-admin%2F&reauth=1 HTTP/2.0" 200 2349 "https://convercon.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
|
Port Scan
|
|
|
πΊπΈ
mnsf
|
|
Scanning/Probing (14)
|
Brute-Force
Web App Attack
|
|
|
π¦πΊ
Anytech
|
|
CrowdSec detected: crowdsecurity/http-sensitive-files
|
Brute-Force
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.3.235 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 22:10:22.642570 2026] [security2:error] [pid 23051:tid 23051] [client 65.111.3.235:45787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kerrywood.com"] [uri "/app/.env"] [unique_id "aZZ_Hrs3wc8Eh1dhfIy6PwAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π©πͺ
Bedios GmbH
|
|
Login credentials theft attempt
|
Hacking
|
|
|
Anonymous
|
|
Fuzzing/Looking for credentials files.
|
Brute-Force
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 65.111.3.235 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 65.111.3.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 15:03:30.837006 2026] [security2:error] [pid 22897:tid 22897] [client 65.111.3.235:64589] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||saadeh.ws|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "saadeh.ws"] [uri "/wp-json/wp/v2/users"] [unique_id "aZYbEmSRehcq4I3h0-CANQAAAAc"], referer: https://www.google.com
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.3.235 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:53:06.684456 2026] [security2:error] [pid 21643:tid 21643] [client 65.111.3.235:18027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thrudheim.org"] [uri "/api/.git/config"] [unique_id "aZYKkjJOY52l0Y_pgTInjwAAAA4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.3.235 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 09:15:09.794355 2026] [security2:error] [pid 764567:tid 764588] [client 65.111.3.235:28617] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wwwhst.com"] [uri "/wp/.git/config"] [unique_id "aZXJbaMdmsrQNCFHiC-DUAAAANI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
mnsf
|
|
Too many Status 40X (11)
Scanning/Probing (11)
|
Brute-Force
Web App Attack
|
|