πͺπΈ
librebit
2026-05-17 06:50:24
(2 weeks ago)
Brute force
Brute-Force
π΅π±
sefinek.net
2026-04-05 00:41:28
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: /genshin-stella-mod | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 β’ Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π«π·
masterguru
2026-03-30 06:22:29
(2 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 65.111.3.54 (US/United States/-): 1 in the las ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 65.111.3.54 (US/United States/-): 1 in the last 3600 secs (0-197)
show less
Hacking
Anonymous
2026-03-29 12:26:54
(2 months ago)
Forum/form spam
Web Spam
π§πͺ
voormedia
2026-02-15 22:06:08
(3 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
π«π·
dynamix
2026-02-15 12:14:03
(3 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
moppetto
2026-02-15 12:11:59
(3 months ago)
Node.js .env file credential scraping; GET /.env
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-02-15 11:36:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:36:25.073824 2026] [security2:error] [pid 32571:tid 32571] [client 65.111.3.54:47913] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pa-ksa.com"] [uri "/admin/.git/config"] [unique_id "aZGvuRK_6CwPGIsLmebUvgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 11:20:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:20:03.326104 2026] [security2:error] [pid 20994:tid 20994] [client 65.111.3.54:63711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sellingcarshandbook.com"] [uri "/app/.git/config"] [unique_id "aZGr4w5uAvMlSfA8-4-5CgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 06:38:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:37:56.805106 2026] [security2:error] [pid 19817:tid 19817] [client 65.111.3.54:14105] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "operationsresearch-management.science"] [uri "/.env.save"] [unique_id "aZFpxBWSpxjJTs86c7OMGQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 06:10:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:10:44.077487 2026] [security2:error] [pid 22107:tid 22157] [client 65.111.3.54:62061] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oneringnetwork.net"] [uri "/api/.git/config"] [unique_id "aZFjZFijoqwdMHNAObPyEgAAAdE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 05:54:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:54:37.733749 2026] [security2:error] [pid 17345:tid 17345] [client 65.111.3.54:17573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "professorjunk.com"] [uri "/.env"] [unique_id "aZFfnU1aPtNPxYGLC76jigAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
AWW-Admin
2026-02-15 05:18:23
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted] 65.111.3.54 (US/United States/-)
SQL Injection
πΊπΈ
mnsf
2026-02-15 05:06:09
(3 months ago)
Scanning/Probing (23)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 05:04:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:04:45.199237 2026] [security2:error] [pid 2499485:tid 2499485] [client 65.111.3.54:39271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oceansgift.com"] [uri "/config/.env"] [unique_id "aZFT7b9UJiFy4A8JrcZx3QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack