Anonymous
2026-06-11 11:54:07
(1 day ago)
Tentative dรฉtectรฉe sur notre infrastructure
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-17 07:01:51
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 02:01:43.865318 2026] [security2:error] [pid 20727:tid 20727] [client 102.212.88.243:35013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aWsz11aE37ek2I9a6WSyTAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 17:53:09
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 12:53:03.466181 2025] [security2:error] [pid 30284:tid 30620] [client 102.212.88.243:53213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.net"] [uri "/.env.kettlehill"] [unique_id "aVK__zko7uys3oTtjZtoxAAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 10:28:43
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 05:28:36.747210 2025] [security2:error] [pid 29971:tid 29971] [client 102.212.88.243:52105] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/moveitisapi/moveitisapi.dll"] [unique_id "aRWy1AZolcBnD-N7mFn8-AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 16:47:32
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 12:47:28.368541 2025] [security2:error] [pid 30110:tid 30148] [client 102.212.88.243:52567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.net"] [uri "/.env.webmail"] [unique_id "aN1bIMkWrLLgoGKIU59AYgAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-06 08:45:04
(9 months ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 00:28:57
(10 months ago)
(mod_security) mod_security (id:211190) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:28:51.766126 2025] [security2:error] [pid 172225:tid 172389] [client 102.212.88.243:51145] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /fuel/pages/select/?filter=%27%2bpi(print(%24a%3d%27system%27))%2b%24a(%27cat%20/etc/passwd%27)%2b%27"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/fuel/pages/select/"] [unique_id "aIVywyMU3kwwovU6SBKTrQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-07-15 00:07:24
(10 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-06-23 16:14:39
(11 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-29 20:40:09
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 16:40:03.650495 2025] [security2:error] [pid 3468536:tid 3468536] [client 102.212.88.243:45913] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.farmers123.com"] [uri "/.env.prod.local"] [unique_id "aDjGI5sLydb4hkeIEeZPSwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-27 17:10:08
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-27 14:58:42
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 09:58:14.829393 2025] [security2:error] [pid 27065:tid 27250] [client 102.212.88.243:37407] [client 102.212.88.243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.kettlehill.net"] [uri "/.env"] [unique_id "Z8B9hidqMyQKEHyZyujHVAAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-06 05:23:22
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 102.212.88.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 06 00:23:15.598159 2025] [security2:error] [pid 9757:tid 9757] [client 102.212.88.243:44319] [client 102.212.88.243] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kingstoneproperties.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kingstoneproperties.com"] [uri "/[email protected] "] [unique_id "Z6RHQ2xei4UqW1KHCrRQqAAAAAo"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyuuzyou
2024-11-17 11:48:48
(1 year ago)
Intensive scraping: /web?s=%22Login%20Form%22%20%22Remember%20Me%22%20%22Log%20in%22%20%22Forgot%20y ...
show more
Intensive scraping: /web?s=%22Login%20Form%22%20%22Remember%20Me%22%20%22Log%20in%22%20%22Forgot%20your%20password%3F%22%20%22Forgot%20your%20username%3F%22%20%22Create%20an%20account%22&country=kj-kj&scraper=wiby. User-Agent: Mozilla/5.0 (Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0.
show less
Bad Web Bot