π§πͺ
Anon
2026-08-09 17:30:00
(2 weeks ago)
www.solidfairhubhost.com
Involved in spamming, see https://www.virustotal.com/gui/domain/solidfai ...
show more
www.solidfairhubhost.com
Involved in spamming, see https://www.virustotal.com/gui/domain/solidfairhubhost.com
show less
Email Spam
Phishing
πΊπΈ
TPI-Abuse
2025-10-08 16:02:05
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 08 12:01:56.497032 2025] [security2:error] [pid 30646:tid 30646] [client 207.244.248.35:49973] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.troop52.org"] [uri "/web.config.zip"] [unique_id "aOaK9G_wbFzHqAl65lh-lwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
updown.io
2025-10-07 14:46:17
(10 months ago)
{"level":"info","ts":1759848372.0392168,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1759848372.0392168,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"207.244.248.35","remote_port":"53022","client_ip":"207.244.248.35","proto":"HTTP/1.1","method":"GET","host":"status.manon-ansart.fr","uri":"/deployment.zip","headers":{"User-Agent":["Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"status.manon-ansart.fr"}},"bytes_read":0,"user_id":"","duration":0.000101729,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1759848372.049946,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"207.244.248.35","remote_port":"53020","client_ip":"207.244.248.35","proto":"HTTP/1.1","method":"GET","host":"status.manon-ansart.fr","uri":"/deploy.zip","headers":{"User-Agent":["M
...
show less
DDoS Attack
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-06 02:22:16
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 22:22:10.218872 2025] [security2:error] [pid 317:tid 317] [client 207.244.248.35:51654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rahjx.net"] [uri "/web.config.zip"] [unique_id "aOMn0k4Rl8Wb3SDdzyIY7QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-06 01:37:38
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 21:37:28.067859 2025] [security2:error] [pid 16317:tid 16317] [client 207.244.248.35:60816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.loveoflearning.com"] [uri "/web.config.zip"] [unique_id "aOMdWCZ0xxDxiTnzVpMOIgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-05 08:13:51
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 04:13:48.638689 2025] [security2:error] [pid 30865:tid 30865] [client 207.244.248.35:57458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swampash.lloydprins.com"] [uri "/web.config.zip"] [unique_id "aOIovPaFI2qjwOvyCivGYgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2025-10-05 02:54:54
(10 months ago)
276 attempts against mh-misbehave-ban on plum
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-04 13:58:47
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 09:58:42.349331 2025] [security2:error] [pid 13040:tid 13040] [client 207.244.248.35:52616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.wedemandavote.com"] [uri "/web.config.zip"] [unique_id "aOEoElyXqfvW7yuowRuHIAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-02 10:13:26
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 06:13:19.935500 2025] [security2:error] [pid 19802:tid 19802] [client 207.244.248.35:54644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.marcosmelero.com"] [uri "/web.config.zip"] [unique_id "aN5QPw99wws1XAJnmnTw_QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-29 22:12:46
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 18:12:41.429387 2025] [security2:error] [pid 14537:tid 14537] [client 207.244.248.35:62799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.powersystemprotection.co.uk"] [uri "/web.config.zip"] [unique_id "aNsEWa2qwhBG1IGBVR_pxwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-29 12:15:52
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 08:15:47.575303 2025] [security2:error] [pid 14486:tid 14486] [client 207.244.248.35:61958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.fagerbergfamily.net"] [uri "/web.config.zip"] [unique_id "aNp4c2ye81YGEWeBTs7VQQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-21 22:20:09
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 21 18:20:00.229171 2025] [security2:error] [pid 24917:tid 24917] [client 207.244.248.35:55258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.remote911.net"] [uri "/web.config.zip"] [unique_id "aNB6EPiHHuncW5CpvSqxbQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-17 20:19:49
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 17 16:19:42.941376 2025] [security2:error] [pid 27576:tid 27608] [client 207.244.248.35:56150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.conservativedemocrat.com"] [uri "/web.config.zip"] [unique_id "aMsX3uiajpU4mMeltPyJLQAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2025-09-13 01:05:14
(11 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-09 12:12:00
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.248.35 (vmi405686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 09 08:11:52.330272 2025] [security2:error] [pid 31545:tid 31545] [client 207.244.248.35:52742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.atmoorehealthcare.com"] [uri "/web.config.zip"] [unique_id "aMAZiKma9msk1XA_-YheXwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack