🇺🇸
craudiovizai
2026-09-04 00:30:32
(1 day ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-login.php. Blocked ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-login.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
🇹🇷
neron
2026-08-11 17:06:48
(3 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
🇹🇷
neron
2026-08-07 18:29:21
(4 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
🇹🇷
neron
2026-08-01 18:32:15
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
🇺🇸
oncord
2026-06-04 19:00:33
(3 months ago)
Form spam
Web Spam
🇺🇸
xmission.com
2026-05-30 01:25:12
(3 months ago)
Blocked by UFW (TCP on 80)
Source port: 32613
TTL: 54
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 32613
TTL: 54
Packet length: 60
TOS: 0x00
This report (for 65.111.8.154) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
🇬🇧
Oakley
2026-04-12 22:38:56
(4 months ago)
(antiscrape_rule) Web application abuse detected 65.111.8.154 (US/United States/-): 5 in the last 90 ...
show more
(antiscrape_rule) Web application abuse detected 65.111.8.154 (US/United States/-): 5 in the last 900 secs
show less
Hacking
🇺🇸
mnsf
2026-02-13 10:06:11
(6 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-02-13 08:29:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 03:29:31.504973 2026] [security2:error] [pid 24558:tid 24558] [client 65.111.8.154:13559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laecovillage.org"] [uri "/api/.env"] [unique_id "aY7g64cB4GBsPdqfqcvafAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-13 07:43:56
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 02:43:49.806928 2026] [security2:error] [pid 28629:tid 28629] [client 65.111.8.154:63675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kwtlaw.com"] [uri "/config/.env"] [unique_id "aY7WNcFM0nq3HKGcq30TBQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-13 06:12:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 01:11:56.351664 2026] [security2:error] [pid 18900:tid 18900] [client 65.111.8.154:49313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koshland.org"] [uri "/admin/.env"] [unique_id "aY7ArJ-PYtnVFfQf_l4_dAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-13 01:38:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 20:38:31.838111 2026] [security2:error] [pid 1081618:tid 1081618] [client 65.111.8.154:30067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathrynsaunders.com"] [uri "/app/.env"] [unique_id "aY6Al43LQSxunX5lZ-xhVQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-13 00:16:42
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 19:16:38.006828 2026] [security2:error] [pid 29096:tid 29096] [client 65.111.8.154:55211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ahuramazda.com"] [uri "/.git/config"] [unique_id "aY5tZoOTQYtu58vtxlBDngAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-02-12 23:00:48
(6 months ago)
Auto-ban: >3000 req/min op 2026-02-12
Hacking
Web App Attack
SSH
🇺🇸
TPI-Abuse
2026-02-12 20:15:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.8.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 15:15:39.334128 2026] [security2:error] [pid 6959:tid 6959] [client 65.111.8.154:54339] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "encoreporchfest.info"] [uri "/.env"] [unique_id "aY4068eYWzFNoFWdYfU86wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack