๐ง๐ช
taivas.nl
2026-06-06 06:32:02
(1 day ago)
Fake_GoogleBot
Bad Web Bot
SSH
๐ต๐ฑ
cheatmaster.store
2026-02-25 23:30:14
(3 months ago)
Automated report: This IP address has been identified as an active public open proxy.
Classification ...
show more
Automated report: This IP address has been identified as an active public open proxy.
Classification: Open Proxy | Spoofing | VPN/Anonymizer | Bad Web Bot.
Country: United Kingdom
Threat level: High. This host is listed across multiple public proxy databases and poses a risk of abuse, credential stuffing, scraping, and spoofed traffic.
Reported by automated threat intelligence pipeline. Do not whitelist without manual verification.
show less
Web Spam
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 14:44:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 09:44:30.818456 2026] [security2:error] [pid 845:tid 845] [client 31.59.33.165:40719] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/sample.htaccess"] [unique_id "aWugTp54E5xcuPi3E56hBwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 20:59:02
(5 months ago)
(mod_security) mod_security (id:221260) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:221260) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 15:58:34.247535 2025] [security2:error] [pid 21770:tid 21780] [client 31.59.33.165:36261] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||webmail.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.com"] [uri "/cgi-bin/stats"] [unique_id "aVLree1IUNfWG5lsn0G3uAAAAYc"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 17:03:04
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 12:02:55.698268 2025] [security2:error] [pid 9768:tid 9768] [client 31.59.33.165:52451] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/windows/win.ini"] [unique_id "aRS9v8y5IM51HXpT-vFLFQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 17:24:06
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 13:24:00.183613 2025] [security2:error] [pid 30110:tid 30160] [client 31.59.33.165:49963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.com"] [uri "/api/.env"] [unique_id "aN1jsMkWrLLgoGKIU59RlwAAAc8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-21 08:30:19
(9 months ago)
Malicious activity detected
Hacking
Web App Attack
๐ช๐ธ
Global Cyber Police
2025-08-20 04:59:34
(9 months ago)
Part of botnet that all have no referrer and always use the exact spoofed agent: Mozilla/5.0 (compat ...
show more
Part of botnet that all have no referrer and always use the exact spoofed agent: Mozilla/5.0 (compatible; crawler)
show less
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
exxos
2025-08-20 03:03:01
(9 months ago)
Attacks with Bad user agents
Hacking
Anonymous
2025-08-19 20:17:17
(9 months ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 01:05:43
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:05:37.811573 2025] [security2:error] [pid 404368:tid 404601] [client 31.59.33.165:49569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kettlehill.net"] [uri "/.env"] [unique_id "aIV7YasKpTtRNU_PZbqUoQAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 17:28:04
(1 year ago)
(mod_security) mod_security (id:212620) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 13:27:54.808595 2025] [security2:error] [pid 3069606:tid 3069606] [client 31.59.33.165:49283] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||ftp.farmers123.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /rm0vxant\\x22><script>alert(document.domain)</script>/..cfide/wizards/common/_authenticatewizarduser.cfm"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "ftp.farmers123.com"] [uri "/RM0VXANT\\"><script>alert(document.domain)</script>/..CFIDE/wizards/common/_authenticatewizarduser.cfm"] [unique_id "aDiZGrkggeW5fcSRv375pAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-19 05:37:26
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.59.33.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 19 01:37:08.142713 2025] [security2:error] [pid 22650:tid 22672] [client 31.59.33.165:56799] [client 31.59.33.165] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.blog.spinningdesigns.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blog.spinningdesigns.com"] [uri "/wp-content/uploads/dump.sql"] [unique_id "aAM2hMLYwl69KqC_78ihJgAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-17 08:40:04
(1 year ago)
| Shellshock attack attempt
Hacking
SQL Injection
Web App Attack