๐ต๐น
Subnet Shadow Specter
2026-07-08 10:30:34
(1 month ago)
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 82.25.216.243 claime ...
show more
[Security] [Category: Bot Masquerading] FCrDNS mismatch detected. [IP Address]: 82.25.216.243 claimed a fake identity but failed forward-confirmed reverse DNS verification. Automated scraping via spoofed User-Agent `compatible; Googlebot/2.1`. [Action]: IP block initiated. [User-Agent]: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) [Date]: 2026-07-08 11:30:33 UTC.
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 11:53:35
(7 months ago)
(mod_security) mod_security (id:240950) triggered by 82.25.216.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240950) triggered by 82.25.216.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 06:53:27.902030 2026] [security2:error] [pid 8680:tid 8680] [client 82.25.216.243:50109] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||cpcalendars.nbcnewsradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/secure/QueryComponentRendererValue!Default.jspa"] [unique_id "aWt4NwnYnJaTPdZVMdTY3QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 21:31:26
(8 months ago)
(mod_security) mod_security (id:240950) triggered by 82.25.216.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240950) triggered by 82.25.216.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 16:31:22.810197 2025] [security2:error] [pid 9999:tid 10016] [client 82.25.216.243:54939] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||cpcontacts.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cpcontacts.kettlehill.com"] [uri "/_users/org.couchdb.user:poc"] [unique_id "aVLzKoun-3ctHNDZklPVYgAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
[email protected]
2025-12-29 06:16:16
(8 months ago)
Attack attempt against Interwebbi servers; *Port Scan* detected from 82.25.216.243 (UA/Ukraine/-). 5 ...
show more
Attack attempt against Interwebbi servers; *Port Scan* detected from 82.25.216.243 (UA/Ukraine/-). 5 hits in the last 360 seconds; IP: 82.25.216.243; Ports: *; Direction: 0; Trigger: PS_LIMIT;
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-13 10:12:31
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 82.25.216.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 82.25.216.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 05:12:24.337198 2025] [security2:error] [pid 22382:tid 22382] [client 82.25.216.243:52007] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/privatekey.key"] [unique_id "aRWvCISiiLkhAKC_5xiOFQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 01:09:40
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 82.25.216.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.25.216.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:09:36.854755 2025] [security2:error] [pid 653296:tid 653325] [client 82.25.216.243:41123] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kettlehill.net"] [uri "/.env"] [unique_id "aIV8UL5epZI5Xx2m9sk6_AAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 19:36:30
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 82.25.216.243 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.25.216.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 15:36:21.886528 2025] [security2:error] [pid 3253280:tid 3253280] [client 82.25.216.243:54687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.farmers123.com"] [uri "/.env.example"] [unique_id "aDi3NauoEboPQzUUDb6WWgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-05 22:00:02
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack