🇨🇿
Countryman
2026-09-04 00:10:01
(1 day ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇩🇪
NxtGenIT
2026-09-03 08:57:26
(2 days ago)
CiscoASA Honeypot hit, Payload: "GET /+CSCOE+/logon.html HTTP/1.1" 302 -,
Brute-Force
Anonymous
2026-08-31 10:46:13
(5 days ago)
Web attack blocked by Wordfence on mergel.nu (1 hit). Reported by CRMON.
Web App Attack
🇮🇹
VHosting
2026-08-29 19:00:05
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
lostswordfish.com
2026-08-28 14:58:03
(1 week ago)
Wordfence waf block on registrymatters
Web App Attack
Anonymous
2025-11-29 19:36:13
(9 months ago)
botnet
DDoS Attack
🇺🇸
TPI-Abuse
2025-11-26 06:45:33
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:45:30.200958 2025] [security2:error] [pid 32748:tid 32748] [client 65.111.5.19:43295] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.craftcare.net"] [uri "/.svn/wc.db"] [unique_id "aSaiCtcvItm6yn6IIuAWVQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 06:08:50
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 01:08:46.450218 2025] [security2:error] [pid 28344:tid 28344] [client 65.111.5.19:11691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pappakotis.com"] [uri "/.git/HEAD"] [unique_id "aSaZbjvJ1vBRbDTC-cr08gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 05:41:57
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:41:53.317290 2025] [security2:error] [pid 5794:tid 5794] [client 65.111.5.19:57241] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thecollective.org"] [uri "/.svn/wc.db"] [unique_id "aSaTIaJp8cue1et6N4VObgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
xmission.com
2025-11-26 05:22:49
(9 months ago)
Blocked by UFW (TCP on 80)
Source port: 42757
TTL: 53
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 42757
TTL: 53
Packet length: 60
TOS: 0x00
This report (for 65.111.5.19) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 03:17:44
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 22:17:38.489371 2025] [security2:error] [pid 21680:tid 21680] [client 65.111.5.19:51009] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kevinjewell.com"] [uri "/.git/HEAD"] [unique_id "aSZxUsuwd1bBgRP6qbHBIQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 02:49:19
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:49:10.467993 2025] [security2:error] [pid 20556:tid 20556] [client 65.111.5.19:12029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.delidalga.chevronparkett.com"] [uri "/.git/HEAD"] [unique_id "aSZqpuFXqQV_m78ULDRfYQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 02:03:59
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:03:55.191139 2025] [security2:error] [pid 10120:tid 10120] [client 65.111.5.19:40761] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thehomedaleinn.com"] [uri "/.git/HEAD"] [unique_id "aSZgC8yZhPqd_u2LVQVBxwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-26 00:41:37
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:41:32.255599 2025] [security2:error] [pid 21527:tid 21527] [client 65.111.5.19:33051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ashburnp.us"] [uri "/.svn/wc.db"] [unique_id "aSZMvH96KQNNxFpp0UngKwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 09:41:24
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:41:16.600040 2025] [security2:error] [pid 14018:tid 14018] [client 65.111.5.19:33827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.firstlivingcell.com"] [uri "/.svn/wc.db"] [unique_id "aSQoPPB0HSjKUucLvArV6gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack