๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
Anonymous
2026-03-11 23:24:53
(2 months ago)
Banned by SPAMHAUS ASN-DROP list (ASN: 200373)
DDoS Attack
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-05 08:08:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 05 03:08:03.207452 2026] [security2:error] [pid 2915:tid 2930] [client 65.111.5.40:40291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howardhallis.com"] [uri "/.git/objects/b7/2df647167196e48c02f9990c9443373639b01b"] [unique_id "aak542bdh7c6FWT9QFVMAgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-25 11:27:26
(3 months ago)
Banned by SPAMHAUS ASN-DROP list (ASN: 200373)
DDoS Attack
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-11-30 13:09:56
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-25 05:28:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:28:39.501306 2025] [security2:error] [pid 11819:tid 11819] [client 65.111.5.40:56879] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cafelimelight.com"] [uri "/.svn/wc.db"] [unique_id "aSU-h0-rfVS8YRZ61lg0zgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:56:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:56:41.712209 2025] [security2:error] [pid 7983:tid 7983] [client 65.111.5.40:19895] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wexfordcap.com"] [uri "/.env"] [unique_id "aSU3CTkckHA4rNOKuJtwzAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:24:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:24:38.387027 2025] [security2:error] [pid 16642:tid 16642] [client 65.111.5.40:16543] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.homerbiz.com"] [uri "/.git/HEAD"] [unique_id "aSUFVrpRG4k4Bv6hRwt1lgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:53:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:53:32.731991 2025] [security2:error] [pid 14823:tid 14823] [client 65.111.5.40:47211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.goodneighborvillage.org"] [uri "/.svn/wc.db"] [unique_id "aST-DGKG7Ev-gsqB-8u2XAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:34:50
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:34:42.124011 2025] [security2:error] [pid 28416:tid 28416] [client 65.111.5.40:38683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.modeltdr.com"] [uri "/.env"] [unique_id "aST5osKv7sNfNjMYeY2kBgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:47:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:47:51.415935 2025] [security2:error] [pid 12103:tid 12157] [client 65.111.5.40:10551] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aussiepens.com"] [uri "/.env"] [unique_id "aSQNp-d3pxroRSWDTtpuewAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:02:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.5.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:01:59.360604 2025] [security2:error] [pid 29659:tid 29659] [client 65.111.5.40:30249] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.derekvantreese.com"] [uri "/.git/HEAD"] [unique_id "aSPYtzUS_u_CoiahnefjEgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 02:20:58
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ญ๐บ
zolav8
2025-11-10 01:18:01
(6 months ago)
SQL injection / web attack attempt
Hacking
SQL Injection
Anonymous
2025-10-16 09:04:40
(7 months ago)
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show more
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less
Brute-Force