|
Anonymous
|
|
65.111.7.127 - - [20/May/2026:06:10:02 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows ...
show more
65.111.7.127 - - [20/May/2026:06:10:02 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
show less
|
Web App Attack
|
|
|
๐ฆ๐บ
afleventoffice.com.au
|
|
GET /.aws/credentials HTTP/1.1
|
Web App Attack
|
|
|
Anonymous
|
|
suspicious request in access.log
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 04:39:44.700953 2026] [security2:error] [pid 5651:tid 5651] [client 65.111.7.127:32821] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||gardner.farm.brazilianbottom.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gardner.farm.brazilianbottom.com"] [uri "/s3cmd.ini"] [unique_id "afByUK_NrB4cfBecEi1z7wAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ช๐ธ
10dencehispahard SL
|
|
Wordpress probing for vulnerabilities
|
Hacking
Exploited Host
|
|
|
๐ซ๐ท
tilellit.pro
|
|
Fail2Ban banned 65.111.7.127 for security violations in jail wp-armour. Log: 2026/01/23 10:45:22 [er ...
show more
Fail2Ban banned 65.111.7.127 for security violations in jail wp-armour. Log: 2026/01/23 10:45:22 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 65.111.7.127 | Target: wplogin" , client: 65.111.7.127, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
|
Web Spam
|
|
|
๐ง๐ช
madeit
|
|
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:10:07.200105 2025] [security2:error] [pid 26519:tid 26519] [client 65.111.7.127:27181] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.infolinkqr.com"] [uri "/.svn/wc.db"] [unique_id "aSQS37ZX8d2q_edtezbKhAAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:37:03.824857 2025] [security2:error] [pid 17750:tid 17750] [client 65.111.7.127:10035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ultrakid.com"] [uri "/.env"] [unique_id "aSQLH4B3H2DiY3UOyx2YEQAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:20:53.706166 2025] [security2:error] [pid 12102:tid 12127] [client 65.111.7.127:11377] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.layoverlocations.com"] [uri "/.git/HEAD"] [unique_id "aSQHVfW9q1mxetu5lC-MGQAAAJU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:08:47.349309 2025] [security2:error] [pid 3504:tid 3504] [client 65.111.7.127:37997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.airlinechristmascards.com"] [uri "/.git/HEAD"] [unique_id "aSPoX950s3kbkeJ4CQZPAAAAABU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:35:34.153894 2025] [security2:error] [pid 3503:tid 3503] [client 65.111.7.127:44231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.valkyriepanthers.com"] [uri "/.env"] [unique_id "aSPglpoQqmoLU2eG8jV5SwAAAAw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 05:53:19.727154 2025] [security2:error] [pid 20704:tid 20704] [client 65.111.7.127:50031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.guardmagic.eu"] [uri "/.env"] [unique_id "aRmtH6TVCEKqkiW7nAg4bQAAABU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
This IP was involved in a brute force and password spray attack.
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
techboy117
|
|
Blocking due to password spraying.
|
Brute-Force
|
|