Anonymous
2026-05-01 12:50:52
(1 month ago)
Banned by SPAMHAUS ASN-DROP list (ASN: 200373)
DDoS Attack
Hacking
Bad Web Bot
Web App Attack
π¦πΊ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
πΊπΈ
TPI-Abuse
2026-01-12 21:24:20
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 16:24:13.994535 2026] [security2:error] [pid 22257:tid 22257] [client 65.111.9.222:56259] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||primacomm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "primacomm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWVmfeb9gYPNHxVvzCBtTAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Packets-Decreaser.NET
2025-12-29 14:01:55
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
πΊπΈ
TPI-Abuse
2025-11-24 09:59:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:59:22.079153 2025] [security2:error] [pid 22919:tid 22919] [client 65.111.9.222:39741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clients.kinareemagazine.com"] [uri "/.git/HEAD"] [unique_id "aSQseqfNit7YBXaocjNV-gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 09:30:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:30:06.527374 2025] [security2:error] [pid 20275:tid 20275] [client 65.111.9.222:32549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ahijado.org"] [uri "/.git/HEAD"] [unique_id "aSQlnn43e_BKx9qp69QFJgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 09:08:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:08:44.301462 2025] [security2:error] [pid 28265:tid 28265] [client 65.111.9.222:20277] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.longbowhunter.gnquivers.com"] [uri "/.git/HEAD"] [unique_id "aSQgnB2Sp9HDizk9IAfe0QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 07:20:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:20:01.999523 2025] [security2:error] [pid 13942:tid 14008] [client 65.111.9.222:58485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jimpepperfest.net"] [uri "/.env"] [unique_id "aSQHIQ9TCbHXOd9uq_efXQAAAcM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 05:37:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:37:47.812995 2025] [security2:error] [pid 3359833:tid 3359833] [client 65.111.9.222:29257] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.healthy4youllc.com"] [uri "/.svn/wc.db"] [unique_id "aSPvK5003kGwyA0hK16c8gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 05:01:51
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:01:44.768104 2025] [security2:error] [pid 5103:tid 5154] [client 65.111.9.222:48513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abney.info"] [uri "/.svn/wc.db"] [unique_id "aSPmuFz8f4PiRLoPAIGp1gAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:05:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:05:03.701900 2025] [security2:error] [pid 26451:tid 26451] [client 65.111.9.222:34355] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fastr-wellington.com"] [uri "/.svn/wc.db"] [unique_id "aSPZb_bIfW4ENHrFDe6cHwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 20:47:47
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-17 23:40:34
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-17 07:50:40
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.17 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.17 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-06 05:22:50
(7 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.06 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.06 is noted in report timestamp
show less
Hacking
Brute-Force