🇵🇹
Subnet Shadow Specter
2026-07-19 12:43:24
(1 month ago)
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 154.6.87.31 claimed ...
show more
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 154.6.87.31 claimed a fake identity but failed forward-confirmed reverse DNS verification. Automated scraping via spoofed User-Agent `compatible; Googlebot/2.1`. [Action]: IP block initiated. [User-Agent]: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) [IoA Datetime]: 2026-07-19 13:43:23 UTC +1.
show less
Port Scan
Hacking
Spoofing
Bad Web Bot
Web App Attack
🇫🇮
Christopher Hughes
2026-07-19 04:16:23
(1 month ago)
154.6.87.31 - - [19/Jul/2026:05:16:22 +0100] "GET /canalsrivers/waterway/leeds--liverpool-canal HTTP ...
show more
154.6.87.31 - - [19/Jul/2026:05:16:22 +0100] "GET /canalsrivers/waterway/leeds--liverpool-canal HTTP/1.1" 200 13165 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
🇫🇷
bigorre.org
2026-05-21 16:34:35
(3 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
🇺🇸
TPI-Abuse
2026-01-17 00:12:16
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210350) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 19:12:08.833493 2026] [security2:error] [pid 23934:tid 23934] [client 154.6.87.31:46305] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ftp.nbcnewsradio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ftp.nbcnewsradio.com"] [uri "/"] [unique_id "aWrT2KpEUS8vL89oKiZlTgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-29 18:45:46
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 13:45:39.818885 2025] [security2:error] [pid 22841:tid 22998] [client 154.6.87.31:34259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.net"] [uri "/.env.live"] [unique_id "aVLMU7vqJPp5jxktaSFybQAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-04 01:32:17
(9 months ago)
(mod_security) mod_security (id:221260) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:221260) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 03 20:32:07.619443 2025] [security2:error] [pid 26195:tid 26195] [client 154.6.87.31:52299] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpcalendars.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.farmers123.com"] [uri "/"] [unique_id "aTDkl8qJyup3lm_dkwc5_AAAABk"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-13 09:05:59
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:04:57.736980 2025] [security2:error] [pid 14559:tid 14559] [client 154.6.87.31:33785] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".nbcnewsradio.com.key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/ssl/ftp.nbcnewsradio.com.key"] [unique_id "aRWfORJTr4wKVHM74L7aaAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
RoboSOC
2025-10-16 08:33:33
(10 months ago)
HTTP Directory Traversal Vulnerability , PTR: PTR record not found
Hacking
🇩🇪
dayda.net
2025-10-13 03:22:51
(10 months ago)
option=com_biblestudy&id=1&view=studieslist&controller=../../../../../../../../etc/passwd
Bad Web Bot
🇺🇸
TPI-Abuse
2025-07-27 01:13:21
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:13:18.389622 2025] [security2:error] [pid 653296:tid 653309] [client 154.6.87.31:48943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/.env.prod.local"] [unique_id "aIV9Lr5epZI5Xx2m9sk-mAAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-05-29 16:34:57
(1 year ago)
(mod_security) mod_security (id:212620) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:212620) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 12:34:49.195200 2025] [security2:error] [pid 2989381:tid 2989381] [client 154.6.87.31:52331] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.farmers123.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /wp-content/plugins/jsmol2wp/php/jsmol.php?isform=true&call=savefile&data=</script><script>alert(document.domain)</script>&mimetype=text/html;charset=utf-8"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.farmers123.com"] [uri "/wp-content/plugins/jsmol2wp/php/jsmol.php"] [unique_id "aDiMqf0_2BMqV4c_q1QYQQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-04-19 05:18:28
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 154.6.87.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 19 01:18:05.608506 2025] [security2:error] [pid 22650:tid 22671] [client 154.6.87.31:50101] [client 154.6.87.31] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.blog.spinningdesigns.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /maint/modules/home/index.php?lang=english|cat%20/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.spinningdesigns.com"] [uri "/maint/modules/home/index.php"] [unique_id "aAMyDcLYwl69KqC_78iWLQAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-28 01:40:05
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack