๐ต๐ฑ
cheatmaster.store
2026-02-25 23:05:31
(3 months ago)
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show more
Automated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: United Kingdom
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less
Web Spam
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 19:11:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 155.254.38.124 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 155.254.38.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:09:52.759792 2025] [security2:error] [pid 22842:tid 22993] [client 155.254.38.124:57079] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kettlehill.com"] [uri "/_.htaccess"] [unique_id "aVLSAFKoonkfA7MmLZcYRAAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
[email protected]
2025-12-29 09:55:28
(5 months ago)
Attack attempt against Interwebbi servers; *Port Scan* detected from 155.254.38.124 (GB/United Kingd ...
show more
Attack attempt against Interwebbi servers; *Port Scan* detected from 155.254.38.124 (GB/United Kingdom/-). 5 hits in the last 300 seconds; IP: 155.254.38.124; Ports: *; Direction: 0; Trigger: PS_LIMIT;
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-13 11:35:31
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 155.254.38.124 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 155.254.38.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 06:35:24.070472 2025] [security2:error] [pid 29822:tid 29822] [client 155.254.38.124:58407] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/img../.git/config"] [unique_id "aRXCfOMH1H75h3svU3LsvAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 00:13:21
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 155.254.38.124 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 155.254.38.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:12:59.745216 2025] [security2:error] [pid 172229:tid 172475] [client 155.254.38.124:52395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.net"] [uri "/wp-config.php.txt"] [unique_id "aIVvC-Zd-uShJ73phjvVDAAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 20:13:27
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 155.254.38.124 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 155.254.38.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 16:13:21.377099 2025] [security2:error] [pid 3409515:tid 3409515] [client 155.254.38.124:47325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.farmers123.com"] [uri "/.env.stage"] [unique_id "aDi_4ezpEUXeBpEvKoQlTAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-19 05:24:47
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 155.254.38.124 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 155.254.38.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 19 01:24:23.396042 2025] [security2:error] [pid 22650:tid 22672] [client 155.254.38.124:40899] [client 155.254.38.124] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.blog.spinningdesigns.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_rsfiles&task=files.display&path=../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.spinningdesigns.com"] [uri "/index.php"] [unique_id "aAMzh8LYwl69KqC_78iZ2AAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-29 04:20:02
(1 year ago)
| XSS (Cross Site Scripting) attempt.
Hacking
SQL Injection
Web App Attack