🇯🇵
warudora
2026-09-09 06:56:34
(1 day ago)
Automated Honeypot Trap: Attempted to access sensitive path '/wp-login.php' on a Flask server.
Hacking
Web App Attack
🇩🇪
iNetWorker
2026-09-08 07:11:33
(2 days ago)
trolling for resource vulnerabilities
Web App Attack
🇨🇿
Countryman
2026-09-05 00:10:02
(5 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇿
Countryman
2026-09-04 01:15:58
(6 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇪🇸
librebit
2026-07-23 04:34:33
(1 month ago)
Brute force
Brute-Force
🇺🇸
TPI-Abuse
2026-02-20 15:49:45
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 10:49:37.521714 2026] [security2:error] [pid 17294:tid 17294] [client 65.111.3.98:37765] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gransla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gransla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZiCkXC6AaethmUZORFvbwAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
MAGIC
2026-02-01 00:13:32
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇩🇪
Packets-Decreaser.NET
2025-12-29 14:01:18
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-12-09 10:51:53
(9 months ago)
botnet
DDoS Attack
Anonymous
2025-11-27 14:27:46
(9 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.11.27 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.11.27 is noted in report timestamp
show less
Hacking
Brute-Force
🇺🇸
TPI-Abuse
2025-11-25 07:17:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:17:23.007251 2025] [security2:error] [pid 31107:tid 31107] [client 65.111.3.98:9729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.garthp.com"] [uri "/.env"] [unique_id "aSVYA23yVt7F2FYXhicGSwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 05:51:03
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:50:57.429289 2025] [security2:error] [pid 28869:tid 28869] [client 65.111.3.98:46853] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kaibeth.com"] [uri "/.svn/wc.db"] [unique_id "aSVDwSzCKjQB043S4KpzBwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 04:43:09
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:43:05.952483 2025] [security2:error] [pid 26451:tid 26451] [client 65.111.3.98:23881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.frameandsavehydepark.com"] [uri "/.git/HEAD"] [unique_id "aSUz2dSsZmv7p-1atPpGDgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 04:10:19
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:10:11.306934 2025] [security2:error] [pid 1278:tid 1291] [client 65.111.3.98:17813] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.i-masmx.com"] [uri "/.git/HEAD"] [unique_id "aSUsI8-5_Q7Y14ElCf2MQgAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-25 03:51:06
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.3.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:51:01.880233 2025] [security2:error] [pid 32765:tid 32765] [client 65.111.3.98:52535] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mothersdaybouquet.net"] [uri "/.env"] [unique_id "aSUnpWWgfyjHAVT7Z2W0bwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack