๐จ๐ฆ
iocwatch
2026-06-07 12:12:46
(4 months ago)
Confirmed bulletproof hosting for pig-butchering investment fraud cluster. Hosts 100+ fraud sites fi ...
show more
Confirmed bulletproof hosting for pig-butchering investment fraud cluster. Hosts 100+ fraud sites fingerprinted with Alibaba CAPTCHA App ID 167omjd. AS30860 YURTEH-AS / AS43641 Sollutium. Domains use sfgfdsaewr CNAME relay. Reported to Spamhaus DBL, Google Safe Browsing, FBI IC3, FTC, RCMP/CAFC, Cogent AS174, Voxility AS3223, Hurricane Electric AS6939.
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 00:20:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 20:20:13.812605 2026] [security2:error] [pid 4680:tid 4680] [client 62.182.83.195:6893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.orlando-windsor-villa.com.robin5on.com"] [uri "/config/.env"] [unique_id "acnBvV9_OHv60S9ijumuMQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 07:42:50
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 03:42:43.534973 2026] [security2:error] [pid 24726:tid 24726] [client 62.182.83.195:34553] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdn.heavyglare.com"] [uri "/.env.backup"] [unique_id "acjX8-L1sjYOZk2p7m9W_wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 19:13:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 15:13:31.075207 2026] [security2:error] [pid 16989:tid 16989] [client 62.182.83.195:35041] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "district7vote.com"] [uri "/.env.backup"] [unique_id "acgoW-YC_VBxcYiO4SOB8QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 08:50:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 04:50:46.668690 2026] [security2:error] [pid 20499:tid 20499] [client 62.182.83.195:56097] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digbiellc.com"] [uri "/web/.env"] [unique_id "aceWZlO_hZK8VwMc7XzcrAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 03:04:56
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 23:04:50.304809 2026] [security2:error] [pid 22422:tid 22422] [client 62.182.83.195:51381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mdgcontrols.motioncontrolpartners.com"] [uri "/.env"] [unique_id "acdFUkI8rOjb9LtBsrf8MQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-03-20 23:00:53
(6 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-03-19.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-03-19 23:04:03
(6 months ago)
Auto-ban: >3000 req/min op 2026-03-19
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-19 11:57:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.195 (mail14.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:57:46.899460 2026] [security2:error] [pid 14850:tid 14850] [client 62.182.83.195:28023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.ptr.com.post-therapyreconditioning.com"] [uri "/web/.env"] [unique_id "abvkuh-SZXrHG4y7zfdZ0gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack