๐บ๐ธ
TPI-Abuse
2026-01-18 00:17:49
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.143.245.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.143.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 19:17:45.869049 2026] [security2:error] [pid 11602:tid 11602] [client 104.143.245.5:46475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/wp-config.php.txt"] [unique_id "aWwmqY3SZYvA0XNw7q-1oAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 18:49:41
(8 months ago)
(mod_security) mod_security (id:240950) triggered by 104.143.245.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240950) triggered by 104.143.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 13:49:17.825930 2025] [security2:error] [pid 22841:tid 22996] [client 104.143.245.5:41029] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||cpcontacts.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cpcontacts.kettlehill.com"] [uri "/_users/org.couchdb.user:poc"] [unique_id "aVLNLbvqJPp5jxktaSF2uAAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2025-10-13 03:21:11
(11 months ago)
query: rest_route=/h5vp/v1/view/1&id=1'+AND+(SELECT+1+FROM+(SELECT(SLEEP(10)))a)--+-
Bad Web Bot
Anonymous
2025-08-19 21:40:05
(1 year ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 01:01:00
(1 year ago)
(mod_security) mod_security (id:212880) triggered by 104.143.245.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212880) triggered by 104.143.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:00:54.042906 2025] [security2:error] [pid 404372:tid 404538] [client 104.143.245.5:60839] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:<style.{0,399}?>.{0,399}?(?:@[i\\\\\\\\]|(?:[:=]|&#x?0*(?:58|3A|61|3D);?).{0,399}?(?:[(\\\\\\\\]|&#x?0*(?:40|28|92|5C);?)))" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "95"] [id "212880"] [rev "4"] [msg "COMODO WAF: IE XSS Filters - Attack Detected.||staging.kettlehill.com|F|2"] [data "Matched Data: 104.143.245.5 found within MATCHED_VAR: <style><j:jelly xmlns:j=\\x22jelly\\x22 xmlns:g='glide'><g:evaluate>gs.adderrormessage(1337*1337);</g:evaluate></j:jelly></style>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "staging.kettlehill.com"] [uri "/login.do"] [unique_id "aIV6RhTdKN3sxMPXSjQDNAAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-24 02:43:55
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
Anonymous
2025-06-22 21:30:30
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-29 17:21:06
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 104.143.245.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.143.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 13:20:56.679878 2025] [security2:error] [pid 3053304:tid 3053304] [client 104.143.245.5:35605] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.farmers123.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.farmers123.com"] [uri "/roundcube/logs/errors.log"] [unique_id "aDiXeDnh_qqedcuxYcUuDAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-19 05:31:02
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 104.143.245.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 104.143.245.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 19 01:29:16.077305 2025] [security2:error] [pid 22650:tid 22663] [client 104.143.245.5:48957] [client 104.143.245.5] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.blog.spinningdesigns.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /wp-content/plugins/mail-masta/inc/lists/csvexport.php?pl=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.spinningdesigns.com"] [uri "/wp-content/plugins/mail-masta/inc/lists/csvexport.php"] [unique_id "aAM0rMLYwl69KqC_78icRAAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-29 01:00:02
(1 year ago)
| SQL injection attempt.
Hacking
SQL Injection
Web App Attack
๐ธ๐ฌ
oncord
2024-09-07 20:49:28
(2 years ago)
Form spam
Web Spam
๐ธ๐ฌ
oncord
2024-09-05 06:20:46
(2 years ago)
Form spam
Web Spam
๐บ๐ธ
nowyouknow
2024-08-29 23:09:21
(2 years ago)
(From [email protected] ) Hi, I'm Jason. I just stumpled upon your website and spotted some a ...
show more
(From [email protected] ) Hi, I'm Jason. I just stumpled upon your website and spotted some areas where some small changes could boost your a lot more leads. I've assisted many clients in your industry improve their websites, and they experienced substantial growth in leads as a result.
I'd be happy to hop on a quick call to discuss these improvements with you. I'm available this week, so at no cost, just to help.
Please tell me the best way to reach you, and we can schedule a time that works for you. It's simple stuff and won't take much time to address.
Best,
Jason Clemens
** Visit: https://bit.ly/FreeWebsiteAuditByJason
Or reply to this email [email protected] or call me at: +1-651-419-8101
show less
Phishing
Web Spam
๐ธ๐ฌ
oncord
2024-08-24 23:20:27
(2 years ago)
Form spam
Web Spam
๐ธ๐ฌ
oncord
2024-08-11 08:26:06
(2 years ago)
Form spam
Web Spam