🇵🇹
Subnet Shadow Specter
2026-07-19 12:05:51
(2 days ago)
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 45.41.162.85 claimed ...
show more
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 45.41.162.85 claimed a fake identity but failed forward-confirmed reverse DNS verification. Automated scraping via spoofed User-Agent `compatible; Googlebot/2.1`. [Action]: IP block initiated. [User-Agent]: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) [IoA Datetime]: 2026-07-19 13:05:50 UTC +1.
show less
Port Scan
Hacking
Spoofing
Bad Web Bot
Web App Attack
🇫🇷
bigorre.org
2026-07-16 10:13:16
(5 days ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
Anonymous
2026-06-22 12:00:00
(4 weeks ago)
Fake Googlebot: User-Agent claims Googlebot/2.1 but the source IP (AS46516 GLOBEIX, US) is outside G ...
show more
Fake Googlebot: User-Agent claims Googlebot/2.1 but the source IP (AS46516 GLOBEIX, US) is outside Google's official IP ranges and has no crawl-*.googlebot.com reverse DNS. 4 requests observed between 2026-05-23 and 2026-06-22.
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-06-01 02:56:26
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:56:20.534914 2026] [security2:error] [pid 7732:tid 7766] [client 45.41.162.85:55611] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.staging.kettlehill.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "staging.kettlehill.com"] [uri "/index.php.bak"] [unique_id "ahz01CKq_i-FrRbJEDIQSQAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-16 16:35:06
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 11:34:59.130858 2026] [security2:error] [pid 9357:tid 9357] [client 45.41.162.85:47441] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".nbcnewsradio.com.key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/ssl/ftp.nbcnewsradio.com.key"] [unique_id "aWpos-8WcyXHfINDmde-ZgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nowyouknow
2026-01-12 02:24:56
(6 months ago)
(From [email protected] )(From [email protected] ) Atención al Encargado de Estrategia Digital ...
show more
(From [email protected] )(From [email protected] ) Atención al Encargado de Estrategia Digital
Hola,
Trabajo ayudando a marcas a mejorar su visibilidad online y quería compartirle una opción sencilla para impulsar su alcance.
La visibilidad correcta marca la diferencia entre pasar desapercibido o crecer. Por eso ayudamos a reforzar señales sociales de forma controlada, con opciones disponibles desde solo 1 $.
¿Por qué trabajar con nosotros?
Tenemos experiencia real en crecimiento digital multicanal, y nos enfocamos en refuerzo progresivo y medible.
Trabajamos con Instagram, YouTube, TikTok, Twitter (X), Facebook, LinkedIn y otras plataformas.
Algunos servicios disponibles desde 1 $:
- Seguidores en Instagram: Refuerce su presencia inicial
- Likes en Instagram: Aumente la interacción visible
- Retweets en Twitter: Gane visibilidad en conversaciones clave
- Seguidores en Facebook: Refuerce su presencia social
- Suscriptores en YouTube: Impulse su canal en fases iniciales
Dis
show less
Phishing
Web Spam
🇺🇸
TPI-Abuse
2025-12-02 21:47:59
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 16:47:55.845562 2025] [security2:error] [pid 19818:tid 19818] [client 45.41.162.85:59751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.farmers123.com"] [uri "/a.htaccess"] [unique_id "aS9eiw0SpbX865D2zt9gmQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-28 23:21:41
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 19:21:36.323147 2025] [security2:error] [pid 30744:tid 30744] [client 45.41.162.85:46245] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nbcnewsradio.com|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nbcnewsradio.com"] [uri "/elmah.axd"] [unique_id "aQFQAJo666-GU1UOk-LNBQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-01 15:36:54
(9 months ago)
(mod_security) mod_security (id:212620) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:36:47.978387 2025] [security2:error] [pid 30110:tid 30150] [client 45.41.162.85:35303] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||mail.kettlehill.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /?post_type=post&s=\\x22><script>alert(/33tf6ecwnx47psniixhmrcjwhpg/)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "mail.kettlehill.com"] [uri "/"] [unique_id "aN1Kj8kWrLLgoGKIU58f_gAAAcU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-26 03:54:57
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 25 23:54:49.804576 2025] [security2:error] [pid 22422:tid 22422] [client 45.41.162.85:58183] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.deandobkin.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.deandobkin.com"] [uri "/server.key"] [unique_id "aNYOifU1DLc7-4WLXRJ5HQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-08-05 19:33:51
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 05 15:33:45.694660 2025] [security2:error] [pid 20841:tid 20841] [client 45.41.162.85:34363] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nbcnewsradio.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nbcnewsradio.com"] [uri "/wp-login.php.bak"] [unique_id "aJJcmVNsaG0yeNr6i98AQgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-08-01 08:38:17
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 04:38:13.750266 2025] [security2:error] [pid 3904810:tid 3904867] [client 45.41.162.85:56155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.com"] [uri "/sample.htaccess"] [unique_id "aIx89UJ0FSJDbzgWj2b7wQAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-06-01 05:54:18
(1 year ago)
(mod_security) mod_security (id:218420) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:218420) triggered by 45.41.162.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 01:53:58.624951 2025] [security2:error] [pid 2256139:tid 2256273] [client 45.41.162.85:56691] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mail.kettlehill.net|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mail.kettlehill.net"] [uri "/cgi-bin/php.exe"] [unique_id "aDvq9nvRuSdZj0PHFrQ5zwAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-28 05:20:04
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
🇦🇺
oncord
2023-08-30 04:04:37
(2 years ago)
Form spam
Web Spam