๐บ๐ธ
TPI-Abuse
2026-05-01 18:45:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 14:45:38.557929 2026] [security2:error] [pid 18035:tid 18035] [client 65.111.2.239:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.globetechsecurities.com"] [uri "/.env"] [unique_id "afT00uurxGwbU8yO-hL1ewAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-01 12:51:06
(1 month ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
Anonymous
2026-04-28 21:57:10
(1 month ago)
Forum/form spam
Web Spam
๐ฌ๐ง
Oakley
2026-04-15 12:24:34
(1 month ago)
(antiscrape_rule) Web application abuse detected 65.111.2.239 (US/United States/-): 5 in the last 90 ...
show more
(antiscrape_rule) Web application abuse detected 65.111.2.239 (US/United States/-): 5 in the last 900 secs
show less
Hacking
๐ฌ๐ง
relianoid.com
2026-04-02 08:06:49
(2 months ago)
POST Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web Spam
Anonymous
2026-03-22 03:17:28
(2 months ago)
Forum/form spam
Web Spam
๐ฑ๐ป
garmtech.com
2026-03-21 01:10:21
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 03-10.65.111.2.239.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 03-10.65.111.2.239.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
Anonymous
2026-02-10 03:23:49
(3 months ago)
Forum/form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-02 23:45:28
(6 months ago)
(mod_security) mod_security (id:210740) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210740) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 18:45:21.594692 2025] [security2:error] [pid 17310:tid 17310] [client 65.111.2.239:56695] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||newcitypark.com|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "newcitypark.com"] [uri "/index.php/"] [unique_id "aS96ERDrPJiJiNGvtokTUAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-27 03:51:58
(6 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.11.27 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.11.27 is noted in report timestamp
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-26 05:51:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:51:33.424361 2025] [security2:error] [pid 8268:tid 8268] [client 65.111.2.239:19845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.doctorhouse.ch"] [uri "/.git/HEAD"] [unique_id "aSaVZddFtu33SX_azHu7cQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:22:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:22:23.497888 2025] [security2:error] [pid 29203:tid 29203] [client 65.111.2.239:37597] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.childrenscliniciws.org"] [uri "/.svn/wc.db"] [unique_id "aSaOj82sFHcel0YqkAonqgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 02:29:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:29:08.057816 2025] [security2:error] [pid 24330:tid 24330] [client 65.111.2.239:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.antitribu.com"] [uri "/.git/HEAD"] [unique_id "aSZl9Ec3X2GykHPNBrf3AgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ธ
Smel
2025-11-26 02:03:11
(6 months ago)
Unauthorized Probe/Connection, Hack -
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2025-11-26 00:57:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:57:21.669131 2025] [security2:error] [pid 10405:tid 10405] [client 65.111.2.239:31727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.alecmcatee.com"] [uri "/.svn/wc.db"] [unique_id "aSZQcXe6XDrR9hA5B_ZJ4gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack