๐ซ๐ท
bigorre.org
2026-08-26 10:20:27
(1 day ago)
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-08-19 04:58:00
(1 week ago)
IPBlock protected site ID [3192-af][s=06].
Major crawler impostor.
Mozilla/5.0 (compatible; Google ...
show more
IPBlock protected site ID [3192-af][s=06].
Major crawler impostor.
Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
show less
Bad Web Bot
๐ต๐น
Subnet Shadow Specter
2026-07-20 03:19:25
(1 month ago)
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 45.41.169.197 claime ...
show more
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 45.41.169.197 claimed a fake identity but failed forward-confirmed reverse DNS verification. Automated scraping via spoofed User-Agent `compatible; Googlebot/2.1`. [Action]: IP block initiated. [User-Agent]: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) [IoA Datetime]: 2026-07-20 04:19:24 UTC +1.
show less
Port Scan
Hacking
Spoofing
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-07-16 01:22:00
(1 month ago)
IPBlock protected site ID [3192-af][s=02].
Major crawler impostor.
Mozilla/5.0 (compatible; Google ...
show more
IPBlock protected site ID [3192-af][s=02].
Major crawler impostor.
Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
show less
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-07-07 17:12:00
(1 month ago)
IPBlock protected site ID [4055-d][s=03].
Major crawler impostor.
Mozilla/5.0 (compatible; Googleb ...
show more
IPBlock protected site ID [4055-d][s=03].
Major crawler impostor.
Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
show less
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-06-20 08:52:00
(2 months ago)
IPBlock protected site ID [4055-d][s=03].
Major crawler impostor.
Mozilla/5.0 (compatible; Googleb ...
show more
IPBlock protected site ID [4055-d][s=03].
Major crawler impostor.
Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
show less
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-06-18 10:20:00
(2 months ago)
IPBlock protected site ID [1438-do].
Major crawler impostor.
Mozilla/5.0 (compatible; Googlebot/2. ...
show more
IPBlock protected site ID [1438-do].
Major crawler impostor.
Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-01 02:29:26
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestre ...
show more
(mod_security) mod_security (id:210730) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:29:21.299629 2026] [security2:error] [pid 12707:tid 12727] [client 45.41.169.197:41985] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.net"] [uri "/error.log"] [unique_id "ahzugfr1zQOtbkd9viUviAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 11:38:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestre ...
show more
(mod_security) mod_security (id:210492) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 06:38:15.042490 2026] [security2:error] [pid 483:tid 649] [client 45.41.169.197:48149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.kettlehill.net"] [uri "/.env.live"] [unique_id "aX87JwMxl-cQ0UzvOvSB4wAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 23:39:24
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestre ...
show more
(mod_security) mod_security (id:210492) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 18:39:20.607878 2026] [security2:error] [pid 18566:tid 18566] [client 45.41.169.197:48441] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nbcnewsradio.com"] [uri "/.env.nbcnewsradio"] [unique_id "aWrMKCVQUUBQG6Wi-K1n7QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 22:41:06
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestre ...
show more
(mod_security) mod_security (id:210492) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 17:41:01.628608 2025] [security2:error] [pid 22900:tid 22900] [client 45.41.169.197:46339] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.farmers123.com"] [uri "/.env.prod"] [unique_id "aS9q_VO2V2DC3DFXXA17lwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-01 21:40:04
(8 months ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 07:13:34
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestre ...
show more
(mod_security) mod_security (id:210492) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 02:13:26.669429 2025] [security2:error] [pid 8488:tid 8563] [client 45.41.169.197:34849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kettlehill.net"] [uri "/api/.env"] [unique_id "aS1AFtZHHfu_5jcVG6pt9gAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 11:01:08
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestre ...
show more
(mod_security) mod_security (id:210730) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 06:01:04.109070 2025] [security2:error] [pid 9332:tid 9332] [client 45.41.169.197:54421] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nbcnewsradio.com"] [uri "/error.log"] [unique_id "aRRo8AQ6XoqWJZzqwv-2IAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-01 14:42:49
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestre ...
show more
(mod_security) mod_security (id:210730) triggered by 45.41.169.197 (ip-45-41-169-197.fibre.fibrestream.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 10:42:46.143553 2025] [security2:error] [pid 8590:tid 8613] [client 45.41.169.197:37929] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.com"] [uri "/dbdump.sql"] [unique_id "aQYcZnl6EaMmM6sQysSWDAAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack