๐ต๐น
Subnet Shadow Specter
2026-07-18 09:46:55
(6 days ago)
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 45.39.4.50 claimed a ...
show more
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 45.39.4.50 claimed a fake identity but failed forward-confirmed reverse DNS verification. Automated scraping via spoofed User-Agent `compatible; Googlebot/2.1`. [Action]: IP block initiated. [User-Agent]: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) [IoA Datetime]: 2026-07-18 10:46:55 UTC +1.
show less
Port Scan
Hacking
Spoofing
Bad Web Bot
Web App Attack
Anonymous
2026-07-08 08:14:04
(2 weeks ago)
LH-Watcher: FAKE_ID [Fake Googlebot]
Bad Web Bot
๐ซ๐ท
Thaliruth
2026-06-17 23:16:39
(1 month ago)
[18/Jun/2026:01:16:39.333160 +0200] ajMq1thIcIhrLHJIQrLdQAAAAE8 45.39.4.50 45948 127.0.0.1 7081
...
Hacking
๐ธ๐ฎ
administrator
2026-06-10 22:18:29
(1 month ago)
2026-06-07 14:30:59,077 fail2ban.actions [1104]: NOTICE [apache-fakegooglebot] Ban 45.39.4.5 ...
show more
2026-06-07 14:30:59,077 fail2ban.actions [1104]: NOTICE [apache-fakegooglebot] Ban 45.39.4.50
2026-06-10 00:10:05,994 fail2ban.actions [1080]: NOTICE [apache-fakegooglebot] Ban 45.39.4.50
2026-06-07 14:30:59,077 fail2ban.actions [1104]: NOTICE [apache-fakegooglebot] Ban 45.39.4.50
2026-06-10 00:10:05,994 fail2ban.actions [1080]: NOTICE [apache-fakegooglebot] Ban 45.39.4.50
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ฆ๐บ
MAGIC
2026-06-08 01:28:18
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-06-02 11:38:59
(1 month ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 22:01:43
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-27.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 21:51:28
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.39.4.50 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.39.4.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 17:51:10.873320 2026] [security2:error] [pid 19457:tid 19457] [client 45.39.4.50:38003] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.badwaterclaims.helpkccare.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.badwaterclaims.helpkccare.org"] [uri "/backup.sql"] [unique_id "ahdnTjYmeGq94JynLyP-nQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:23:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.39.4.50 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.39.4.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:23:10.560096 2026] [security2:error] [pid 15778:tid 15778] [client 45.39.4.50:45991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "photoboutiqueamerica.com"] [uri "/.env.backup"] [unique_id "ahY5bgTxIk1jpaw5HE3F7wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 17:54:48
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.39.4.50 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.39.4.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 13:54:37.988133 2026] [security2:error] [pid 22956:tid 22956] [client 45.39.4.50:37347] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ncparanormalresearch.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ncparanormalresearch.com"] [uri "/terraform.tfstate.backup"] [unique_id "ahXeXWtTWJOeybyai0tD6AAAAA0"], referer: https://www.google.com/search?q=ncparanormalresearch.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 16:26:19
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 45.39.4.50 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:949110) triggered by 45.39.4.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 12:26:13.174942 2026] [security2:error] [pid 4505:tid 4505] [client 45.39.4.50:35531] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "boraborapearlbookings.com"] [uri "/db_backup.sql"] [unique_id "ahXJpcaIfBsuYIk_DnH0ewAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack