๐ฆ๐บ
oncord
2026-05-24 22:25:46
(1 week ago)
Form spam
Web Spam
๐ซ๐ท
conseilgouz
2026-05-20 21:32:11
(2 weeks ago)
upw-(visforms) : try to access forms...
Hacking
๐ฑ๐ป
garmtech.com
2026-05-20 18:14:25
(2 weeks ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-14.65.111.0.188.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 21-14.65.111.0.188.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-16 11:44:21
(2 weeks ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 14-44.65.111.0.188.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 14-44.65.111.0.188.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฆ๐บ
oncord
2026-05-11 10:49:01
(3 weeks ago)
Form spam
Web Spam
๐จ๐ญ
backslash
2026-05-10 23:12:01
(3 weeks ago)
Web Spam
๐ง๐ฌ
cheatmaster.store
2026-02-26 05:40:26
(3 months ago)
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show more
Automated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: United States
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less
Web Spam
Port Scan
Web App Attack
๐บ๐ธ
mnsf
2026-02-15 12:05:31
(3 months ago)
Too many Status 40X (11)
Scanning/Probing (15)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 12:05:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.188 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 07:05:01.140621 2026] [security2:error] [pid 23519:tid 23519] [client 65.111.0.188:16389] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qosmexico.com"] [uri "/test/.git/config"] [unique_id "aZG2bUEnv-fpm4A7ed3awQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-15 11:24:05
(3 months ago)
65.111.0.188 - - [15/Feb/2026:11:23:47 +0000] "GET /admin/.env HTTP/1.1" 403 2406 "-" "Mozilla/5.0 ( ...
show more
65.111.0.188 - - [15/Feb/2026:11:23:47 +0000] "GET /admin/.env HTTP/1.1" 403 2406 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 11:02:42
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.188 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:02:35.302126 2026] [security2:error] [pid 27586:tid 27586] [client 65.111.0.188:51213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "punctuminteractive.com"] [uri "/backend/.env"] [unique_id "aZGnyy6ZXV43aApzeo7eqwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 07:09:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.188 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 02:09:45.543755 2026] [security2:error] [pid 32706:tid 32706] [client 65.111.0.188:47403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ptfea.org"] [uri "/.env.save"] [unique_id "aZFxOa9AvglU1i5EkCKwyAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-02-15 06:47:04
(3 months ago)
(modsecurity) srv201 ModSecurity 65.111.0.188 (US/United States/-): 5 in the last 3600 secs; Ports: ...
show more
(modsecurity) srv201 ModSecurity 65.111.0.188 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ซ๐ท
dynamix
2026-02-15 06:28:48
(3 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 05:00:24
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.188 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.188 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:00:20.380458 2026] [security2:error] [pid 28609:tid 28609] [client 65.111.0.188:23531] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarawagnergrants.com"] [uri "/.env.production"] [unique_id "aZFS5NB8zHkrjRv4S1l0oAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack