π¨π¦
iocwatch
2026-06-07 12:12:48
(3 months ago)
Confirmed bulletproof hosting for pig-butchering investment fraud cluster. Hosts 100+ fraud sites fi ...
show more
Confirmed bulletproof hosting for pig-butchering investment fraud cluster. Hosts 100+ fraud sites fingerprinted with Alibaba CAPTCHA App ID 167omjd. AS30860 YURTEH-AS / AS43641 Sollutium. Domains use sfgfdsaewr CNAME relay. Reported to Spamhaus DBL, Google Safe Browsing, FBI IC3, FTC, RCMP/CAFC, Cogent AS174, Voxility AS3223, Hurricane Electric AS6939.
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-30 03:03:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 23:03:19.939676 2026] [security2:error] [pid 24326:tid 24326] [client 62.182.83.215:55113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "probeanalysis.com.afjm.net"] [uri "/config/.env"] [unique_id "acnn93WIxIGoSeD_F2dB_gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-28 22:37:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 18:36:57.094895 2026] [security2:error] [pid 26308:tid 26308] [client 62.182.83.215:51593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "casadelsolmexico.net"] [uri "/.env.backup"] [unique_id "achYCemgIau7xvodhSiRlwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-28 13:47:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 09:47:27.105500 2026] [security2:error] [pid 4274:tid 4274] [client 62.182.83.215:3009] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canonarizona.com"] [uri "/.env.save"] [unique_id "acfb72d3Q4vFbf7bLhnCDQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Ba-Yu
2026-03-28 13:30:18
(6 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
π³π±
Site.eu
2026-03-28 12:18:17
(6 months ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
TPI-Abuse
2026-03-28 11:56:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 07:56:07.261632 2026] [security2:error] [pid 3020:tid 3020] [client 62.182.83.215:36493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "campnecon.com"] [uri "/.env.save"] [unique_id "acfB1_c4PRrf8CrWoUVrvAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
nekopavel
2026-03-28 08:36:49
(6 months ago)
62.182.83.215 - - [28/Mar/2026:09:36:47 +0100]"GET /.env.local HTTP/1.1" 404 118"-" mail.pavel.gg "M ...
show more
62.182.83.215 - - [28/Mar/2026:09:36:47 +0100]"GET /.env.local HTTP/1.1" 404 118"-" mail.pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36""0.000" "0.000""Kyiv" "UA"
62.182.83.215 - - [28/Mar/2026:09:36:47 +0100]"GET /api/.env HTTP/1.1" 404 118"-" mail.pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36""0.000" "0.001""Kyiv" "UA"
62.182.83.215 - - [28/Mar/2026:09:36:47 +0100]"GET /.env.example HTTP/1.1" 404 118"-" mail.pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36""0.000" "0.000""Kyiv" "UA"
...
show less
Hacking
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-03-20 23:00:47
(6 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-03-19.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-03-19 11:13:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:13:39.819365 2026] [security2:error] [pid 16552:tid 16552] [client 62.182.83.215:64817] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.securityzonepr.com"] [uri "/.env.backup"] [unique_id "abvaY1FUv3Hr3Ly-plmIpwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 10:44:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:44:31.365978 2026] [security2:error] [pid 10396:tid 10396] [client 62.182.83.215:6361] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10mostwantedfugitives.net"] [uri "/.git/config"] [unique_id "abvTj44eq0oaBm2sHyp0lwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 08:28:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.215 (mail34.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 04:27:59.764587 2026] [security2:error] [pid 1237:tid 1237] [client 62.182.83.215:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.c2cservices.com"] [uri "/.env.bak"] [unique_id "abuzjzyZgQy76LwCZoDchgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack