๐ซ๐ท
Sklurk
2026-07-29 00:29:42
(3 days ago)
Web App Attack
Web App Attack
๐ฆ๐บ
LiftUp Hosting
2026-06-10 04:45:57
(1 month ago)
Honeypot hit: HTTP/1.1 request on 8546
POST /
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
...
show more
Honeypot hit: HTTP/1.1 request on 8546
POST /
User-Agent: Go-http-client/1.1
Accept-Encoding: gzip
POST Data: {"jsonrpc":"2.0","method":"eth_chainId","params":[],"id":1}; 8546 [2] TCP
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-19 01:26:04
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 20:25:51.018216 2026] [security2:error] [pid 23170:tid 23170] [client 65.111.5.162:39515] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kampinenlaw.com"] [uri "/admin/.env"] [unique_id "aZZmn20ypwpL0NGMoRq3agAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 23:10:28
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 18:10:25.411496 2026] [security2:error] [pid 14119:tid 14136] [client 65.111.5.162:43167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "venezuelaguia.com"] [uri "/site/.git/config"] [unique_id "aZZG4c7LbDS5IjHn1_w05QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 19:41:27
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 14:41:22.159240 2026] [security2:error] [pid 20462:tid 20462] [client 65.111.5.162:61161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tonydelov.net"] [uri "/dev/.git/config"] [unique_id "aZYV4rAs1PWekLLJWXSRbgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-02-18 18:38:31
(5 months ago)
(modsecurity) srv101 ModSecurity 65.111.5.162 (US/United States/-): 5 in the last 3600 secs; Ports: ...
show more
(modsecurity) srv101 ModSecurity 65.111.5.162 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 18:31:08
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:31:01.840427 2026] [security2:error] [pid 5649:tid 5649] [client 65.111.5.162:63795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thevillageartcenter.com"] [uri "/backup/.git/config"] [unique_id "aZYFZYE3ckrOMS6gf2xvnQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 16:39:02
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 11:38:57.367812 2026] [security2:error] [pid 4817:tid 4831] [client 65.111.5.162:9763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yubasutterphotographer.com"] [uri "/.env.staging"] [unique_id "aZXrIVphMObGR2uq3Jf_tQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 13:19:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 08:19:46.602686 2026] [security2:error] [pid 28876:tid 28876] [client 65.111.5.162:32185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "williammaderas.com"] [uri "/backup/.git/config"] [unique_id "aZW8cksvWp1C3I0JXQo82wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-02-18 12:36:35
(5 months ago)
(modsecurity) srv102 ModSecurity 65.111.5.162 (US/United States/-): 5 in the last 3600 secs; Ports: ...
show more
(modsecurity) srv102 ModSecurity 65.111.5.162 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:35:00
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:34:53.213505 2026] [security2:error] [pid 23647:tid 23647] [client 65.111.5.162:46617] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weddinganniversarynapkins.com"] [uri "/config/.env"] [unique_id "aZWx7XzCsLBW7MzjbdvZEAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:08:24
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:08:10.016463 2026] [security2:error] [pid 4754:tid 4754] [client 65.111.5.162:43619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waxjet510.com"] [uri "/api/.env"] [unique_id "aZWrqmxVNpwkig7uFtLOCQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-01-13 22:32:56
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
stinpriza
2026-01-12 20:50:23
(6 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-03 03:19:30
(7 months ago)
(mod_security) mod_security (id:210740) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210740) triggered by 65.111.5.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 22:19:20.885689 2025] [security2:error] [pid 29602:tid 29602] [client 65.111.5.162:10413] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||linhsbridal.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "linhsbridal.com"] [uri "/Guestbook.php"] [unique_id "aS-sOGS2VM4jJIQWTtCabwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack