🇹🇷
agah.balta
2026-09-08 07:31:56
(1 day ago)
PMG Spam Score: 19.0. Hits: FROM_FMBLA_NEWDOM(1.499), GOOG_REDIR_HTML_ONLY(1.499), GOOG_REDIR_NORDNS ...
show more
PMG Spam Score: 19.0. Hits: FROM_FMBLA_NEWDOM(1.499), GOOG_REDIR_HTML_ONLY(1.499), GOOG_REDIR_NORDNS(1.499), KAM_GOOGLE_FRESH_REDIR(2), KAM_GOOGLE_REDIR(1.5), RCVD_IN_SBL_CSS(3.558), RDNS_NONE(5), URIBL_DBL_MALWARE(2.5)
show less
Email Spam
Hacking
🇹🇭
thaizone.com
2026-09-08 07:06:43
(1 day ago)
High probability of spam (Score: 50.00)
Email Spam
🇩🇪
FD-IX
2026-09-08 05:37:58
(1 day ago)
SMTP connection rejected due to combined.mail.abusix.zone listing.
Email Spam
🇹🇭
thaizone.com
2026-09-08 05:36:06
(1 day ago)
High probability of spam (Score: 113.70)
Email Spam
Anonymous
2026-09-08 05:28:15
(1 day ago)
SIEM ALERT AUTO REPORT
Email Spam
🇷🇴
SpamStopper
2026-09-08 05:10:35
(1 day ago)
Fail2Ban - POSTFIX DNSBL listed sender
Email Spam
🇹🇷
ferique
2026-09-08 04:51:58
(1 day ago)
Real-time Intercept: Email Spam. Reference: Tagged as Spam by SpamAssassin. Score 28/10
Email Spam
🇨🇭
Origon
2026-09-08 04:40:07
(1 day ago)
NOQUEUE - IP: 5.252.103.56 - Sep 8 06:40:07 plesk postfix/smtpd[2915873]: NOQUEUE: reject: RCPT fro ...
show more
NOQUEUE - IP: 5.252.103.56 - Sep 8 06:40:07 plesk postfix/smtpd[2915873]: NOQUEUE: reject: RCPT from mail.vegfreshfarm.com[5.252.103.56]: 554 5.7.1 Service unavailable; Client host [5.252.103.56] blocked using dnsbl-2.uceprotect.net; Net 5.252.100.0/22 is UCEPROTECT-Level2 listed because 12 impacts are seen from ITP-SOLUTIONS, DE/AS213250 there. See: http://www.uceprotect.net/rblcheck.php?ipr=5.252.103.56; from=<[email protected] > to=<REDACTED@REDACTED> proto=ESMTP helo=<vegfreshfarm.com>
show less
Email Spam
🇺🇸
TPI-Abuse
2025-10-18 10:10:15
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 5.252.103.56 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.252.103.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 18 06:10:11.715891 2025] [security2:error] [pid 17134:tid 17134] [client 5.252.103.56:37784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eboredom.net"] [uri "/.env.local"] [unique_id "aPNng2nwv32MXX2QKUEn_AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-18 00:58:59
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 5.252.103.56 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.252.103.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 17 20:58:51.794556 2025] [security2:error] [pid 23254:tid 23254] [client 5.252.103.56:54934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigbikers.net"] [uri "/.env.bak"] [unique_id "aPLmS1xYTMJvpgyJVk4_IQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-18 00:08:04
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 5.252.103.56 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.252.103.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 17 20:07:59.895792 2025] [security2:error] [pid 22375:tid 22375] [client 5.252.103.56:34848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bccoa.net"] [uri "/.env.development.local"] [unique_id "aPLaX-tTbx7c_VPJg-wFRAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2025-10-17 22:25:58
(10 months ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2025-10-17 20:13:37
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 5.252.103.56 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.252.103.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 17 16:13:33.927734 2025] [security2:error] [pid 24362:tid 24362] [client 5.252.103.56:49666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adj-tech.net"] [uri "/api/.env"] [unique_id "aPKjbbOt-sz1nMGx3-ZrMAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
jjnxpct
2025-10-17 03:45:10
(10 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env.old (Rule ID: 210492)
show less
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2025-10-16 21:59:49
(10 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2025-10-15.
show less
Hacking
Web App Attack
SSH