π±π»
garmtech.com
2026-05-15 00:55:44
(3 weeks ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 03-55.65.111.14.232.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 03-55.65.111.14.232.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
π±π»
garmtech.com
2026-05-14 23:54:37
(3 weeks ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-54.65.111.14.232.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-54.65.111.14.232.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
π¬π§
PeravixGroup
2026-05-08 22:44:10
(4 weeks ago)
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severit ...
show more
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
π¨π³
ThreatBook.io
2026-05-04 23:05:23
(1 month ago)
ThreatBook Intelligence: http_proxy,Gateway more details on https://threatbook.io/ip/65.111.14.232
2 ...
show more
ThreatBook Intelligence: http_proxy,Gateway more details on https://threatbook.io/ip/65.111.14.232
2026-05-04 21:54:32 /
show less
Web App Attack
π¦πΊ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
π±π»
garmtech.com
2026-02-28 20:52:58
(3 months ago)
IM360 WAF: WordPress plugin/theme auto install block
Web App Attack
π¦π±
cheatmaster.store
2026-02-27 01:12:14
(3 months ago)
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show more
Automated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: United States
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less
Web Spam
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 13:42:24
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 08:42:18.291217 2026] [security2:error] [pid 30718:tid 30839] [client 65.111.14.232:9487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lead-sleds.com"] [uri "/app/.git/config"] [unique_id "aY8qOhnEObaE8PLu9qd80AAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
MM-bot
2026-02-13 13:32:20
(3 months ago)
URL-probe: HTTP/1.1 GET request on /backup/.git/config (2026-02-13 14:32:20 UTC+1)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 08:48:20
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 03:48:15.473293 2026] [security2:error] [pid 12613:tid 12613] [client 65.111.14.232:40203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "messengersforchrist.com"] [uri "/site/.git/config"] [unique_id "aY7lT4astS5GGMAg2nrz0QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 08:09:03
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 03:08:54.876720 2026] [security2:error] [pid 22880:tid 22880] [client 65.111.14.232:17273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "menafert.com"] [uri "/.env.local"] [unique_id "aY7cFoP7p5vro7CoLsMpagAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
0x44
2026-02-13 07:13:06
(3 months ago)
65.111.14.232 [13/Feb/2026] * Spam host detected, probing for vulnerabilities
Web Spam
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 06:43:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 01:43:36.993733 2026] [security2:error] [pid 7781:tid 7781] [client 65.111.14.232:52045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medcoarabia.com"] [uri "/.env.save"] [unique_id "aY7IGO6AoJizwmFgKRexEgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 04:58:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 23:58:39.897082 2026] [security2:error] [pid 1957274:tid 1957312] [client 65.111.14.232:55117] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mastersofthesecrets.com"] [uri "/dev/.git/config"] [unique_id "aY6vfzfMF1PpzQkxSxqyLgAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-13 04:32:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.14.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 23:32:30.162139 2026] [security2:error] [pid 12504:tid 12504] [client 65.111.14.232:19859] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marxistphilosophy.org"] [uri "/v2/.git/config"] [unique_id "aY6pXsi949d2ZFjmR9U0IAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack