๐ซ๐ท
mail.avx.gr
2026-08-22 12:53:49
(2 hours ago)
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 65.111.30.217 - - [22/Aug/2026:15:53:49 +0300] "PO ...
show more
Plesk Fail2Ban jail: Plesk-WebScanners. Evidence: 65.111.30.217 - - [22/Aug/2026:15:53:49 +0300] "POST /wp-login.php HTTP/2.0" 403 1110 "https://candiatrade.gr/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:119.0) Gecko/20100101 Firefox/119.0"
show less
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-15 03:08:49
(1 week ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 217.30.111.65.rbl.malwa ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 217.30.111.65.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-3)
show less
Hacking
๐ซ๐ท
Sklurk
2026-07-31 01:08:34
(3 weeks ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 15:46:29
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 10:46:20.842701 2025] [security2:error] [pid 21769:tid 21769] [client 65.111.30.217:44085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paavoharkonen.com"] [uri "/.git/HEAD"] [unique_id "aS8JzIVhPPUPZI9oqXjU5wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 12:03:00
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 07:02:55.374343 2025] [security2:error] [pid 12373:tid 12373] [client 65.111.30.217:33423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "donzie.com"] [uri "/.git/HEAD"] [unique_id "aS7Vb3mDICud3G4YAxey-wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:11:40
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:11:33.881154 2025] [security2:error] [pid 26074:tid 26074] [client 65.111.30.217:40161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bright-enterprise.com"] [uri "/.env"] [unique_id "aS51BXUry6-hclfuiLqk3gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 03:56:23
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 22:56:16.044745 2025] [security2:error] [pid 27286:tid 27286] [client 65.111.30.217:44621] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "majesticsolutions.co"] [uri "/.env"] [unique_id "aS5jYIRJuFnCi5O-LlQZQgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 19:13:48
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 14:13:43.282157 2025] [security2:error] [pid 3315424:tid 3315438] [client 65.111.30.217:22269] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aafminstitute.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aafminstitute.com"] [uri "/backup.sql"] [unique_id "aSn0Z9EPeXoM8C_lHxwYhgAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 16:35:39
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.30.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 11:35:31.883785 2025] [security2:error] [pid 31153:tid 31153] [client 65.111.30.217:31357] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amdavies15.com"] [uri "/.env"] [unique_id "aSnPU5vS4JvwcuQtExxN-AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-11-10 07:06:20
(9 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2024-07-11 10:06:17
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH