๐จ๐ฆ
iocwatch
2026-06-07 12:12:48
(3 months ago)
Confirmed bulletproof hosting for pig-butchering investment fraud cluster. Hosts 100+ fraud sites fi ...
show more
Confirmed bulletproof hosting for pig-butchering investment fraud cluster. Hosts 100+ fraud sites fingerprinted with Alibaba CAPTCHA App ID 167omjd. AS30860 YURTEH-AS / AS43641 Sollutium. Domains use sfgfdsaewr CNAME relay. Reported to Spamhaus DBL, Google Safe Browsing, FBI IC3, FTC, RCMP/CAFC, Cogent AS174, Voxility AS3223, Hurricane Electric AS6939.
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-03-30 07:20:37
(6 months ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 06:24:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 02:23:56.314928 2026] [security2:error] [pid 22423:tid 22423] [client 62.182.83.217:13439] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iiiip.org"] [uri "/public/.env"] [unique_id "acoW_B93gfmC4rFemG6FbQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 05:07:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 01:07:09.338793 2026] [security2:error] [pid 24880:tid 24880] [client 62.182.83.217:20557] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "words.gmacguffin.com"] [uri "/.env.old"] [unique_id "acoE_WoRF766EnDchcANagAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 02:20:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 22:19:55.118320 2026] [security2:error] [pid 21818:tid 21818] [client 62.182.83.217:4431] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "art.drjaymissdiana.com"] [uri "/.env.production"] [unique_id "aciMS6NHbqrKD-LiOi4KKgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 23:17:24
(6 months ago)
(mod_security) mod_security (id:212620) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:212620) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 19:17:18.531499 2026] [security2:error] [pid 22128:tid 22128] [client 62.182.83.217:17137] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.naijabasket.com.awani-partners.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /?t=<script>alert(1)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.naijabasket.com.awani-partners.com"] [uri "/"] [unique_id "achhfsvtgG498_T0O5hLcwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 14:16:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 10:16:16.883215 2026] [security2:error] [pid 1953:tid 1953] [client 62.182.83.217:2201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "capassoart.com"] [uri "/.env.save"] [unique_id "acfisFWdhRG1WAbjxR6a9wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 13:14:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 09:14:15.291532 2026] [security2:error] [pid 16741:tid 16741] [client 62.182.83.217:62167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "app.s1global.net.s1global.net"] [uri "/api/.env"] [unique_id "acfUJ2aonv2C_VG2dt2UVwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 09:39:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 05:39:14.328528 2026] [security2:error] [pid 2301:tid 2301] [client 62.182.83.217:56067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mintgames.com.danged.com"] [uri "/.env.backup"] [unique_id "acehwt7-Pei1Owfe-YZa1AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 06:48:50
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 02:48:42.401821 2026] [security2:error] [pid 9900:tid 9900] [client 62.182.83.217:50509] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "californiabrokers.californiaappraisers.net"] [uri "/.env.save"] [unique_id "acd5yiGMZloyUgizazPXWQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-03-19 23:05:19
(6 months ago)
Auto-ban: >3000 req/min op 2026-03-19
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-19 10:53:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 62.182.83.217 (mail36.mstacrueacc.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:53:10.841765 2026] [security2:error] [pid 28804:tid 28804] [client 62.182.83.217:40605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.wealthsec.com"] [uri "/src/.env"] [unique_id "abvVlmM4QKo3dFIZl3dazAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack