🇸🇪
OnTheEdge
2026-09-04 03:21:55
(16 hours ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇩🇪
NxtGenIT
2026-09-03 02:10:42
(1 day ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html HTTP/1.1" 302 -,
Brute-Force
Anonymous
2026-08-20 10:36:04
(2 weeks ago)
Botnets flood DDoS activity
DDoS Attack
🇫🇷
Sklurk
2026-08-10 06:20:40
(3 weeks ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-30 00:03:10
(1 month ago)
Web App Attack
Web App Attack
🇦🇺
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
🇩🇪
iNetWorker
2026-01-11 08:28:39
(7 months ago)
trolling for resource vulnerabilities
Web App Attack
🇮🇹
VHosting
2025-12-30 03:00:15
(8 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇨🇭
backslash
2025-12-29 04:20:10
(8 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇺🇸
TPI-Abuse
2025-12-29 04:08:49
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.4.206 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.4.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:08:39.211645 2025] [security2:error] [pid 23640:tid 23640] [client 65.111.4.206:14557] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nickmontfort.com"] [uri "/.svn/wc.db"] [unique_id "aVH-x_oObtazGVGw4vMRZAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 12:58:03
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.4.206 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.4.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 07:57:54.082299 2025] [security2:error] [pid 6739:tid 6739] [client 65.111.4.206:15695] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadinglogan.com"] [uri "/.env"] [unique_id "aTluUnx1EjVZAQ6KDYrWIgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 10:10:06
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.4.206 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.4.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 05:10:00.562529 2025] [security2:error] [pid 18508:tid 18508] [client 65.111.4.206:45483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tesacate.com"] [uri "/.env"] [unique_id "aTlG-BDTbWmchghjaG04ZwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 01:53:03
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.4.206 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.4.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 20:52:58.835317 2025] [security2:error] [pid 18254:tid 18257] [client 65.111.4.206:23151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "veralogistica.com"] [uri "/.git/HEAD"] [unique_id "aTjSeqj-REh1P9Z8J4KJJgAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-09 02:13:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.4.206 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.4.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 21:13:12.312345 2025] [security2:error] [pid 32754:tid 32754] [client 65.111.4.206:19067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johncyphers.com"] [uri "/.env"] [unique_id "aTeFuDfx0gnWiOpu6_OANgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
myagent.site
2025-12-08 18:39:25
(8 months ago)
Blocking for trying to access an exploit file: /.env
Hacking