🇺🇸
drewf.ink
2026-09-04 01:46:10
(4 days ago)
[01:46] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[01:46] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
🇫🇷
Sklurk
2026-08-14 08:26:58
(3 weeks ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-29 02:05:08
(1 month ago)
Web App Attack
Web App Attack
🇪🇸
librebit
2026-05-17 03:54:05
(3 months ago)
Brute force
Brute-Force
🇩🇪
DocNetzwerk
2026-05-06 13:04:32
(4 months ago)
*Port Scan* detected from 65.111.3.29 (US/United States/-).
Port Scan
🇬🇧
relianoid.com
2026-01-30 04:52:50
(7 months ago)
POST Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web Spam
🇺🇸
ambor
2025-12-29 12:22:23
(8 months ago)
Spam submission via ambor.com contact form. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 12.5; ...
show more
Spam submission via ambor.com contact form. User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 12.5; rv:114.0) Gecko/20100101 Firefox/114.0. Timestamp: 2025-12-29T12:22:23.089Z
show less
Web Spam
🇬🇧
relianoid.com
2025-12-07 08:55:13
(9 months ago)
POST Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web Spam
🇺🇸
TPI-Abuse
2025-12-02 22:07:27
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 17:07:24.178239 2025] [security2:error] [pid 6483:tid 6483] [client 65.111.3.29:48771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "njoyquilts.com"] [uri "/.svn/wc.db"] [unique_id "aS9jHJFEZ4OWAcVBIM-Q8gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 15:29:39
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 10:29:34.331224 2025] [security2:error] [pid 8001:tid 8001] [client 65.111.3.29:56597] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "basselier.com"] [uri "/.git/HEAD"] [unique_id "aS8F3hmBPsU94QFmRQJbLwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 08:45:24
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 03:45:18.791618 2025] [security2:error] [pid 15934:tid 15934] [client 65.111.3.29:23579] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "samuelpaley.com"] [uri "/.env"] [unique_id "aS6nHkCBKAOOwkiq4tzQQQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 08:19:06
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 03:19:03.231232 2025] [security2:error] [pid 22751:tid 22751] [client 65.111.3.29:33509] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barillaequipment.com"] [uri "/.git/HEAD"] [unique_id "aS6g9_X0ccn9IwSzAteV5QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 05:48:54
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:48:50.754771 2025] [security2:error] [pid 19325:tid 19325] [client 65.111.3.29:30791] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitality-webb.com"] [uri "/.svn/wc.db"] [unique_id "aS59wp7g7S_9wUZlkSIZ2gAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 04:13:01
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:12:54.091369 2025] [security2:error] [pid 12019:tid 12019] [client 65.111.3.29:27783] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toepert.com"] [uri "/.svn/wc.db"] [unique_id "aS5nRhyDIhuVYvcSq5hxmwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2025-11-25 23:02:06
(9 months ago)
Auto-ban: >3000 req/min op 2025-11-25
Hacking
Web App Attack
SSH