๐บ๐ธ
TPI-Abuse
2026-05-22 00:12:46
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 98.87.17.62 (ec2-98-87-17-62.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 98.87.17.62 (ec2-98-87-17-62.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 20:12:39.766405 2026] [security2:error] [pid 4191:tid 4191] [client 98.87.17.62:55829] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.calvarycavaliers.org"] [uri "/.env"] [unique_id "ag-fd5yezhS0ys76qWzP4wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
xveil
2026-03-25 01:43:13
(5 months ago)
2026-03-25T08:43:10.957794 mail-honeypot postfix/submission/smtpd[21815]: warning: ec2-98-87-17-62.c ...
show more
2026-03-25T08:43:10.957794 mail-honeypot postfix/submission/smtpd[21815]: warning: ec2-98-87-17-62.compute-1.amazonaws.com[98.87.17.62]: SASL LOGIN authentication failed: authentication failure
...
show less
Brute-Force
๐บ๐ธ
oncord
2026-03-12 04:14:20
(6 months ago)
Form spam
Web Spam
๐บ๐ธ
nowyouknow
2026-03-12 04:04:18
(6 months ago)
(From [email protected] ) Hey,
I hope you're doing well. I wanted to let you know about ...
show more
(From [email protected] ) Hey,
I hope you're doing well. I wanted to let you know about our new BANGE backpacks and sling bags that just released.
The bags are waterproof and anti-theft, and have a built-in USB cable that can recharge your phone while you're on the go.
Both bags are made of durable and high-quality materials, and are perfect for everyday use or travel.
Order yours now at 50% OFF with FREE Shipping: http://bangeshop.com
Sincerely,
Gidget
show less
Phishing
Web Spam
Anonymous
2026-03-09 05:11:59
(6 months ago)
RUPLDE WEBFORM SPAM 98.87.17.62 (ec2-98-87-17-62.compute-1.amazonaws.com)
Web Spam
๐ฉ๐ช
FeG Deutschland
2026-03-09 03:34:24
(6 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฆ๐บ
oncord
2026-03-09 01:29:34
(6 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-03-08 17:43:52
(6 months ago)
(mod_security) mod_security (id:217280) triggered by 98.87.17.62 (ec2-98-87-17-62.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:217280) triggered by 98.87.17.62 (ec2-98-87-17-62.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 08 13:43:44.731589 2026] [security2:error] [pid 10167:tid 10199] [client 98.87.17.62:59425] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||omniuscorp.com|F|2"] [data "Matched Data: put found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "omniuscorp.com"] [uri "/"] [unique_id "aa21UG7gCFmx8Y1CxjCXTwAAAME"], referer: https://omniuscorp.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2026-03-08 17:33:28
(6 months ago)
(From [email protected] ) Hello there
I wanted to reach out and let you know about our new dog h ...
show more
(From [email protected] ) Hello there
I wanted to reach out and let you know about our new dog harness. It's really easy to put on and take off - in just 2 seconds - and it's personalized for each dog.
Plus, we offer a lifetime warranty so you can be sure your pet is always safe and stylish.
We've had a lot of success with it so far and I think your dog would love it.
Get yours today with 50% OFF: https://caredogbest.com
FREE Shipping - TODAY ONLY!
Many Thanks,
Eric
show less
Phishing
Web Spam
๐บ๐ธ
nowyouknow
2026-03-06 22:14:00
(6 months ago)
(From [email protected] ) Morning
I wanted to reach out and let you know about our n ...
show more
(From [email protected] ) Morning
I wanted to reach out and let you know about our new dog harness. It's really easy to put on and take off - in just 2 seconds - and it's personalized for each dog.
Plus, we offer a lifetime warranty so you can be sure your pet is always safe and stylish.
We've had a lot of success with it so far and I think your dog would love it.
Get yours today with 50% OFF: https://caredogbest.com
FREE Shipping - TODAY ONLY!
Best regards,
Shad
show less
Phishing
Web Spam
๐บ๐ธ
oncord
2026-03-06 21:53:26
(6 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-03-06 09:59:45
(6 months ago)
(mod_security) mod_security (id:217280) triggered by 98.87.17.62 (ec2-98-87-17-62.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:217280) triggered by 98.87.17.62 (ec2-98-87-17-62.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 06 04:59:42.374642 2026] [security2:error] [pid 13209:tid 13209] [client 98.87.17.62:53047] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\n|\\\\r)+(?:get|post|head|options|connect|put|delete|trace|propfind|propatch|mkcol|copy|move|lock|unlock)\\\\s+" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "137"] [id "217280"] [rev "6"] [msg "COMODO WAF: HTTP Request Smuggling Attack||www.kreweofblackbeardsrevenge.com|F|2"] [data "Matched Data: put found within MATCHED_VAR"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.kreweofblackbeardsrevenge.com"] [uri "/contact_us.html"] [unique_id "aaqljposx-9EIzTzdbfiHAAAAAY"], referer: https://www.kreweofblackbeardsrevenge.com/contact_us.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Kinsei Engineering Inc.
2026-02-18 17:12:32
(7 months ago)
2026/02/19 02:12:20 [error] 185331#185331: *34656 directory index of "/Web/join/wp-content/uploads/2 ...
show more
2026/02/19 02:12:20 [error] 185331#185331: *34656 directory index of "/Web/join/wp-content/uploads/2020/11/" is forbidden, client: 98.87.17.62, server: www.kinsei.jp, request: "GET /wp-content/uploads/2020/11/ HTTP/2.0", host: "www.kinsei.jp", referrer: "https://www.kinsei.jp/"
2026/02/19 02:12:22 [error] 185329#185329: *34669 directory index of "/Web/join/wp-content/uploads/2022/05/" is forbidden, client: 98.87.17.62, server: www.kinsei.jp, request: "GET /wp-content/uploads/2022/05/ HTTP/2.0", host: "www.kinsei.jp", referrer: "https://www.kinsei.jp/"
2026/02/19 02:12:31 [error] 185329#185329: *34650 directory index of "/Web/join/wp-content/uploads/2025/11/" is forbidden, client: 98.87.17.62, server: www.kinsei.jp, request: "GET /wp-content/uploads/2025/11/ HTTP/2.0", host: "www.kinsei.jp", referrer: "https://www.kinsei.jp/"
show less
Brute-Force
Web Spam
๐ต๐ฑ
ketovoila.pl
2026-02-16 00:33:38
(7 months ago)
ketovoila.pl HONEYPOT traffic: count=1, paths=1; sample_path=ketovoila.pl/; UA=Mozilla/5.0 (X11; Fed ...
show more
ketovoila.pl HONEYPOT traffic: count=1, paths=1; sample_path=ketovoila.pl/; UA=Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0; window=2026-02-16T00:03:49Z..2026-02-16T00:03:49Z
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-09 09:47:40
(7 months ago)
(mod_security) mod_security (id:217291) triggered by 98.87.17.62 (ec2-98-87-17-62.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:217291) triggered by 98.87.17.62 (ec2-98-87-17-62.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 04:47:33.618058 2026] [security2:error] [pid 32535:tid 32535] [client 98.87.17.62:61062] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\nfromwhere. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||briancastle.com|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cnfromwhere: \\x0d\\x0afromwhere"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "briancastle.com"] [uri "/g12terms.php"] [unique_id "aYmtNdlHSBsEOIkfOVKKUwAAAAA"], referer: http://briancastle.com
show less
Brute-Force
Bad Web Bot
Web App Attack