๐ต๐ฑ
cheatmaster.store
2026-02-25 23:32:33
(3 months ago)
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show more
Automated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: United Kingdom
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less
Web Spam
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 04:59:21
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 23:59:14.053083 2026] [security2:error] [pid 17462:tid 17462] [client 162.220.246.164:58727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/wp-config.php.old"] [unique_id "aWsXIv0tKaUlG46XB1lk4wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 18:43:32
(5 months ago)
(mod_security) mod_security (id:226830) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:226830) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 13:43:24.826814 2025] [security2:error] [pid 22838:tid 22908] [client 162.220.246.164:51069] ModSecurity: Access denied with code 403 (phase 1). Operator GE matched 1 at ARGS_GET. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6392"] [id "226830"] [rev "2"] [msg "COMODO WAF: Open redirect vulnerability in the Redirect function in the StageShow plugin before 5.0.9 for WordPress (CVE-2015-5461)||cpanel.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "cpanel.kettlehill.com"] [uri "/wp-content/plugins/stageshow/stageshow_redirect.php"] [unique_id "aVLLzOHXaA_hkms52yNvSwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 09:52:16
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:52:06.651602 2025] [security2:error] [pid 28416:tid 28416] [client 162.220.246.164:53403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/.env.www"] [unique_id "aRWqRj0OoR35GIHOvJGPiAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-09-17 07:50:02
(9 months ago)
IP was involved in L7 DDoS attack.
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 01:05:15
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:05:09.019079 2025] [security2:error] [pid 653296:tid 653330] [client 162.220.246.164:51117] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kettlehill.net"] [uri "/wp-config.php~"] [unique_id "aIV7Rb5epZI5Xx2m9skyfAAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-07-03 10:10:08
(11 months ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 17:20:35
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 13:20:24.810747 2025] [security2:error] [pid 3061746:tid 3061746] [client 162.220.246.164:52509] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.farmers123.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /LetsEncrypt/Index?fileName=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.farmers123.com"] [uri "/LetsEncrypt/Index"] [unique_id "aDiXWIC-Ap9o7mOUNa7DYwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-04 08:33:37
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:221260) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 04 04:33:21.701572 2025] [security2:error] [pid 3754015:tid 3754015] [client 162.220.246.164:45675] [client 162.220.246.164] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpanel.nbcnewsradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nbcnewsradio.com"] [uri "/403.shtml"] [unique_id "aBcmUfw35MACBzFBuZW7xwAAAA8"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-19 05:26:04
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 19 01:25:32.709105 2025] [security2:error] [pid 22650:tid 22659] [client 162.220.246.164:34965] [client 162.220.246.164] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.blog.spinningdesigns.com|F|2"] [data ".cs"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blog.spinningdesigns.com"] [uri "/nonauth/expiration.cs"] [unique_id "aAMzzMLYwl69KqC_78iajgAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-27 14:34:58
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.220.246.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 09:34:10.392719 2025] [security2:error] [pid 27062:tid 27197] [client 162.220.246.164:48983] [client 162.220.246.164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.staging.kettlehill.com"] [uri "/.env.prod"] [unique_id "Z8B34ggBT3qhfe6UoI1ADwAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-17 08:30:08
(1 year ago)
| XSS (Cross Site Scripting) attempt.
Hacking
SQL Injection
Web App Attack