๐บ๐ธ
PhishFort
2026-10-09 07:46:45
(1 day ago)
Brand abuse: fake affiliation, fake content, impersonation, investment scam
Phishing
Bad Web Bot
๐บ๐ธ
PhishFort
2026-10-09 03:29:13
(1 day ago)
Scam: investment scam
Phishing
Bad Web Bot
๐บ๐ธ
PhishFort
2026-10-07 23:50:20
(2 days ago)
Scam: investment scam
Phishing
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-07 19:46:40
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 163.61.237.11 (starlord.globaldnsnetwork.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 163.61.237.11 (starlord.globaldnsnetwork.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:46:34.717445 2026] [security2:error] [pid 18337:tid 18337] [client 163.61.237.11:48688] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dianamead.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dianamead.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asahmmMmKWmude2Xmbu-6AAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 15:54:43
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 163.61.237.11 (starlord.globaldnsnetwork.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 163.61.237.11 (starlord.globaldnsnetwork.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 11:54:36.037459 2026] [security2:error] [pid 15024:tid 15024] [client 163.61.237.11:51856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||convtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "convtek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asZrPGeFIwbt6Ix8YVVlLgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-07 13:55:54
(3 days ago)
Web exploit attempt | method: GET | path: /wp-json/wp/v2/users | ua: Mozilla/5.0 (Windows NT 10.0; W ...
show more
Web exploit attempt | method: GET | path: /wp-json/wp/v2/users | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-07 00:45:15
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:28:37
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 163.61.237.11 (starlord.globaldnsnetwork.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 163.61.237.11 (starlord.globaldnsnetwork.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:28:29.611297 2026] [security2:error] [pid 11263:tid 11263] [client 163.61.237.11:48174] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.solucionesmercadeodigital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.solucionesmercadeodigital.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asVn_Rs4tHiHygW3Q9hsMQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 19:35:24
(4 days ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:00:06
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 163.61.237.11 (starlord.globaldnsnetwork.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 163.61.237.11 (starlord.globaldnsnetwork.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 09:59:55.519602 2026] [security2:error] [pid 3041:tid 3045] [client 163.61.237.11:35080] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||41bravo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "41bravo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asT-29I7o_NDM6XivY4lDAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
PhishFort
2026-10-06 11:57:16
(4 days ago)
Scam: investment scam
Phishing
Bad Web Bot
๐ฎ๐ช
cleanerweb
2026-10-05 14:51:00
(5 days ago)
lytehosting.com still hosting 419 advanced fee fraud scam sites (163.61.188.2 / 163.61.188.5 / 163.6 ...
show more
lytehosting.com still hosting 419 advanced fee fraud scam sites (163.61.188.2 / 163.61.188.5 / 163.61.188.7 / 163.61.236.12 / 163.61.237.11)
dns1.lytehosting.com
dns2.lytehosting.com
dns1.globaldnsnetwork.com
dns2.globaldnsnetwork.com
here are some of the scam sites hosted here:
globaltradeshift.com | fake investment scam
globalmarketholding.live | fake investment scam
avestcanadbank.com | fake bank scam
pfcreditunion.com | fake bank scam
trustflow.top | fake bank scam
avextrade.com | fake investment scam
qaventadb.com | fake bank scam
masecosfinance.com | fake investment scam
stratovacapsltd.pro | fake investment scam
show less
Phishing
๐บ๐ธ
TPI-Abuse
2026-10-02 15:59:08
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 163.61.237.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 163.61.237.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:59:00.592853 2026] [security2:error] [pid 25278:tid 25278] [client 163.61.237.11:41856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||constructiondomex.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "constructiondomex.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ar_UxO180dZlTrDKUasE1AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-30 23:10:04
(1 week ago)
Detected mail brute force attack from different servers
Brute-Force