๐ต๐ฑ
cheatmaster.store
2026-02-25 23:28:33
(3 months ago)
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show more
Automated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: United Kingdom
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less
Web Spam
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 08:38:06
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 03:37:55.905049 2026] [security2:error] [pid 13053:tid 13053] [client 31.59.20.93:55035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.live"] [unique_id "aWtKY86SG-329iM2Nr-sDAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 17:52:18
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 12:52:02.926149 2025] [security2:error] [pid 30292:tid 30606] [client 31.59.20.93:47533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kettlehill.com"] [uri "/wp-content/plugins/jsmol2wp/php/jsmol.php"] [unique_id "aVK_woGwzh_8AlcRvOiH3QAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 00:46:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 19:46:13.552477 2025] [security2:error] [pid 13584:tid 13626] [client 31.59.20.93:41863] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.kettlehill.com"] [uri "/media../.git/config"] [unique_id "aSjw1eb7YZ3SjyQOwqY8tAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 09:29:16
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:29:07.831904 2025] [security2:error] [pid 12206:tid 12206] [client 31.59.20.93:42043] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/.env.bak"] [unique_id "aRWk42X3OzWef_5u_RQhAQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 02:33:30
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 22:33:24.330594 2025] [security2:error] [pid 729657:tid 729695] [client 31.59.20.93:47985] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/.env.example"] [unique_id "aIWP9BUVDjlJfvQpjEJyCgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-21 19:28:23
(10 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
Anonymous
2025-06-22 20:23:26
(11 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-30 01:15:45
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 21:15:39.697297 2025] [security2:error] [pid 3895403:tid 3895403] [client 31.59.20.93:41671] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||mail.farmers123.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /magmi/web/ajax_pluginconf.php?file=../../../../../../../../../../../etc/passwd&plugintype=utilities&pluginclass=CustomSQLUtility"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.farmers123.com"] [uri "/magmi/web/ajax_pluginconf.php"] [unique_id "aDkGu6W8Q6ULJHkTpr-fBgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2025-05-21 14:08:36
(1 year ago)
query: option=com_pro_desk&include_file=../../../../../../etc/passwd
Bad Web Bot
๐บ๐ธ
Vincent Helmus
2025-05-16 17:40:19
(1 year ago)
ALL
DNS Compromise
DNS Poisoning
Fraud Orders
DDoS Attack
FTP Brute-Force
Ping of Death
Phishing
Fraud VoIP
Open Proxy
Web Spam
Email Spam
Blog Spam
VPN IP
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐บ๐ธ
TPI-Abuse
2025-05-04 08:37:27
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 04 04:37:21.446513 2025] [security2:error] [pid 3757059:tid 3757059] [client 31.59.20.93:54813] [client 31.59.20.93] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nbcnewsradio.com"] [uri "/.env.development.local"] [unique_id "aBcnQYR9VcJHy87MO40J-QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-19 03:11:46
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.20.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 18 23:10:41.613028 2025] [security2:error] [pid 14944:tid 14969] [client 31.59.20.93:50675] [client 31.59.20.93] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.spinningdesigns.com"] [uri "/wp-config.php.html"] [unique_id "aAMUMalkjOMtrQ4IEmnjCgAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-09 08:12:19
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
Anonymous
2025-01-26 02:40:20
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack