๐ต๐ฑ
cheatmaster.store
2026-02-25 23:15:41
(4 months ago)
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show more
Automated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: United Kingdom
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less
Web Spam
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 19:18:26
(5 months ago)
(mod_security) mod_security (id:211190) triggered by 198.105.100.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 198.105.100.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:18:20.026939 2025] [security2:error] [pid 31734:tid 31757] [client 198.105.100.10:34663] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /card_scan.php?No=30&ReaderNo=%60cat%20/etc/passwd%20%3E%20owTWdYvrzt.txt%60"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/card_scan.php"] [unique_id "aVLT_GCDVM70TD0LIjvbeQAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
RoboSOC
2025-10-16 08:37:33
(8 months ago)
vBulletin SQL Injection Vulnerability, PTR: PTR record not found
Hacking
๐บ๐ธ
TPI-Abuse
2025-10-01 15:02:11
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 198.105.100.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.105.100.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:00:46.165650 2025] [security2:error] [pid 9487:tid 9521] [client 198.105.100.10:35681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.kettlehill.net"] [uri "/.env.bak"] [unique_id "aN1CHkvyOqnYEaX7Ie4ZpgAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
exxos
2025-09-08 03:03:01
(9 months ago)
Attacks with Bad user agents
Hacking
๐ฉ๐ช
SCHAPPY
2025-09-04 20:50:05
(9 months ago)
IP was involved in L7 DDoS attack.
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 01:13:20
(10 months ago)
(mod_security) mod_security (id:211190) triggered by 198.105.100.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 198.105.100.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:13:11.408406 2025] [security2:error] [pid 404369:tid 404469] [client 198.105.100.10:37925] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||staging.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /webEdition/showTempFile.php?file=../../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/webEdition/showTempFile.php"] [unique_id "aIV9J41ApCwrT9-Kn8XBBgAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-22 22:09:38
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-29 19:28:10
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 198.105.100.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 198.105.100.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 15:27:48.562298 2025] [security2:error] [pid 3287216:tid 3287216] [client 198.105.100.10:50527] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpcalendars.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.farmers123.com"] [uri "/cgi-bin/test-cgi"] [unique_id "aDi1NAIsS2fgIhIqDn_uxQAAAA4"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-27 15:02:18
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 198.105.100.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.105.100.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 09:59:18.696418 2025] [security2:error] [pid 27063:tid 27230] [client 198.105.100.10:35891] [client 198.105.100.10] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.kettlehill.net"] [uri "/.env.autoconfig"] [unique_id "Z8B9xsnGgNPGej7DPucTcwAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-15 09:30:11
(1 year ago)
| SQL injection attempt.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
nowyouknow
2024-08-30 05:31:54
(1 year ago)
(From [email protected] ) Unlock your $32,220 tax credit when you partner SETC PROS, โthis oppor ...
show more
(From [email protected] ) Unlock your $32,220 tax credit when you partner SETC PROS, โthis opportunity expires in April 2025. Secure your savings today!
++ Claim now: https://bit.ly/setcpros
You can unsubscribe by sending an email with subject "Unsubscribe" to [email protected]
2 Kingsway North, Holtye Common, NA, Great Britain, Tn8 0hn
show less
Phishing
Web Spam
๐ธ๐ฌ
oncord
2024-08-29 19:58:29
(1 year ago)
Form spam
Web Spam
๐ธ๐ฌ
oncord
2024-08-23 18:49:01
(1 year ago)
Form spam
Web Spam
๐ธ๐ฌ
oncord
2024-08-11 08:12:08
(1 year ago)
Form spam
Web Spam