🇩🇪
NxtGenIT
2026-09-04 00:59:54
(3 days ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html?fcadbadd=1 HTTP/1.1" 200 -,
Brute-Force
🇨🇿
Countryman
2026-09-03 22:32:09
(3 days ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇺🇸
lostswordfish.com
2026-08-09 11:54:04
(4 weeks ago)
Wordfence waf block on uvfousor WPIDD
Web App Attack
🇺🇸
cwytech
2026-07-30 16:11:07
(1 month ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
🇩🇪
stinpriza
2026-07-25 05:37:38
(1 month ago)
Web App Attack
Web App Attack
🇩🇪
stinpriza
2026-07-23 03:01:36
(1 month ago)
Web App Attack
Web App Attack
Anonymous
2026-05-12 05:57:32
(3 months ago)
65.111.31.215 - - [12/May/2026:07:57:32 +0200] "GET http:///wp-json/gravitysmtp/v1/tests/mock-data?p ...
show more
65.111.31.215 - - [12/May/2026:07:57:32 +0200] "GET http:///wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 301 169 "-" "curl/8.7.1"
show less
Bad Web Bot
Anonymous
2026-03-20 09:26:11
(5 months ago)
Forum/form spam
Web Spam
Anonymous
2026-02-15 11:23:46
(6 months ago)
65.111.31.215 - - [15/Feb/2026:11:23:41 +0000] "GET /.env HTTP/1.1" 302 477 "-" "Mozilla/5.0 (Window ...
show more
65.111.31.215 - - [15/Feb/2026:11:23:41 +0000] "GET /.env HTTP/1.1" 302 477 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 11:11:01
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.31.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.31.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:10:54.347534 2026] [security2:error] [pid 26177:tid 26177] [client 65.111.31.215:38047] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ourcritterguy.com"] [uri "/.git/config"] [unique_id "aZGpvoy1eEBmySwe8NBdJgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-02-15 11:01:51
(6 months ago)
Multiple WAF Violations
Web App Attack
🇮🇩
Burayot
2026-02-15 10:59:04
(6 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 65.111.31.215 (FR/France/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 65.111.31.215 (FR/France/-): 1 in the last 3600 secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 10:54:35
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.31.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.31.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 05:54:32.063199 2026] [security2:error] [pid 8585:tid 8585] [client 65.111.31.215:22941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seebeexee.com"] [uri "/.git/config"] [unique_id "aZGl6IM6WAza9dJGlch1NAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 07:12:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.31.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.31.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 02:06:45.720674 2026] [security2:error] [pid 401774:tid 401774] [client 65.111.31.215:44459] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sebog.org"] [uri "/.env.save"] [unique_id "aZFwhbc3UkVftrTLS-7d7QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 06:55:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.31.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.31.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:55:00.777671 2026] [security2:error] [pid 3796:tid 3796] [client 65.111.31.215:20101] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "orchestrateyouraptitudes.com"] [uri "/app/.git/config"] [unique_id "aZFtxIuylflrdkj5RRPlrgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack