Anonymous
2026-09-04 18:04:01
(18 hours ago)
Bad Web Bot
🇫🇷
Sklurk
2026-08-04 02:45:03
(1 month ago)
Web App Attack
Web App Attack
🇨🇭
4server
2026-05-19 03:24:03
(3 months ago)
[TueMay1905:24:00.4882772026][security2:error][pid3328116:tid3328119][client65.111.30.23:0]ModSecuri ...
show more
[TueMay1905:24:00.4882772026][security2:error][pid3328116:tid3328119][client65.111.30.23:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"367\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"giuristifriburgo.ch\"][uri\"/xmlrpc.php\"][unique_id\"agvX0LGtv78mwKpe27AfyAAAAME\"]
show less
Hacking
Web App Attack
🇱🇻
garmtech.com
2026-04-03 04:27:28
(5 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 07-27.65.111.30.23.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 07-27.65.111.30.23.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 20:07:40
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 15:07:34.971349 2025] [security2:error] [pid 26542:tid 26542] [client 65.111.30.23:28963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cauchosindustrialesespeciales.com"] [uri "/.svn/wc.db"] [unique_id "aS9HBj5vTzZ-ZubhalaprgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 15:17:16
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 10:17:08.569213 2025] [security2:error] [pid 9621:tid 9621] [client 65.111.30.23:49459] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marisetravel.com"] [uri "/.git/HEAD"] [unique_id "aS8C9OVOFrMw4573pinzLQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 12:41:26
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 07:41:20.946681 2025] [security2:error] [pid 424354:tid 424412] [client 65.111.30.23:36259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "delapiazza.com"] [uri "/.env"] [unique_id "aS7ecEEx8a5AyelV2PFQ6wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 12:06:07
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 07:05:59.174171 2025] [security2:error] [pid 28776:tid 28776] [client 65.111.30.23:35197] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dalebeyer.com"] [uri "/.svn/wc.db"] [unique_id "aS7WJzBRcvkFrFARrIZd9wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 06:03:06
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 01:02:59.131219 2025] [security2:error] [pid 14372:tid 14372] [client 65.111.30.23:55487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teenybikini.com"] [uri "/.env"] [unique_id "aS6BEzE_DZ-HABEsY4cgnwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 04:47:03
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 23:46:56.252679 2025] [security2:error] [pid 24905:tid 24905] [client 65.111.30.23:17549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mahoninginn.com"] [uri "/.svn/wc.db"] [unique_id "aS5vQDJ9iK4VsKlZMK-tcgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2025-12-02 00:50:42
(9 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
Anonymous
2025-11-26 16:30:53
(9 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇱🇻
garmtech.com
2025-11-26 07:44:29
(9 months ago)
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 02:20:47
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:20:44.108704 2025] [security2:error] [pid 29965:tid 29965] [client 65.111.30.23:55223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.al-ketab.net"] [uri "/.git/HEAD"] [unique_id "aSZj_BsdigWAcpzyOakqDgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 02:49:09
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 21:49:03.751424 2025] [security2:error] [pid 29894:tid 29894] [client 65.111.30.23:21705] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.designsbykennedy.com"] [uri "/.git/HEAD"] [unique_id "aSPHn7e_akd0YYNOQ13NnwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack