🇺🇸
TPI-Abuse
2026-09-01 20:04:48
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 16:04:41.869566 2026] [security2:error] [pid 663881:tid 664067] [client 104.222.187.12:56455] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.com"] [uri "/data.db"] [unique_id "apcv2cRs2qT7a7W3G-tzBQAAAI4"], referer: https://www.kettlehill.com/data.db
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:46:43
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:46:16.484123 2026] [security2:error] [pid 24745:tid 24745] [client 104.222.187.12:41915] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nbcnewsradio.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nbcnewsradio.com"] [uri "/inetpub.db"] [unique_id "apIPuCBUrDXR_80KgzFx4QAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-05 01:43:38
(4 months ago)
Malicious activity detected
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2025-12-03 02:18:59
(9 months ago)
(mod_security) mod_security (id:221260) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 21:18:41.782258 2025] [security2:error] [pid 18343:tid 18343] [client 104.222.187.12:46311] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||webmail.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.farmers123.com"] [uri "/403.shtml"] [unique_id "aS-eARvB_MzUh5uV3rxK2wAAACE"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-08-06 01:17:41
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 05 21:17:38.435983 2025] [security2:error] [pid 22272:tid 22272] [client 104.222.187.12:39457] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nbcnewsradio.com"] [uri "/example.htaccess"] [unique_id "aJKtMvmIATrvqcprrxuMIAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Cyber SOC
2024-09-10 09:17:26
(1 year ago)
Peaksys - 2024-09-10 10:15:48 UTC+01
Hacking
SQL Injection
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-09-03 18:51:52
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 14:51:41.978884 2024] [security2:error] [pid 8859:tid 8859] [client 104.222.187.12:45129] [client 104.222.187.12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.stdavids-media.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.stdavids-media.com"] [uri "/host.key"] [unique_id "ZtdavdvQ-54TbkPMSzW1AQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-08-26 23:09:05
(2 years ago)
(mod_security) mod_security (id:221260) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 26 19:07:44.844461 2024] [security2:error] [pid 529544:tid 529618] [client 104.222.187.12:40755] [client 104.222.187.12] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpcontacts.kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kettlehill.net"] [uri "/cgi-bin/test"] [unique_id "Zs0KwAXOM9l8qzVVH2Y5HgAAAcM"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ps-center
2024-07-15 18:11:34
(2 years ago)
SS1: Web Attack GET /.ssh/known_hosts.old
Web Spam
Hacking
Bad Web Bot
Web App Attack
🇪🇸
10dencehispahard SL
2024-07-14 00:06:32
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
🇩🇪
dayda.net
2024-07-13 11:17:33
(2 years ago)
query: ../../../../../../../../etc/passwd
Bad Web Bot
🇺🇸
TPI-Abuse
2024-05-28 23:01:36
(2 years ago)
(mod_security) mod_security (id:212620) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:212620) triggered by 104.222.187.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 28 19:01:29.258115 2024] [security2:error] [pid 14928:tid 47260702004992] [client 104.222.187.12:54213] [client 104.222.187.12] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||kettlehill.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /wp-login.php?login-error=<script>alert(document.domain)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "kettlehill.com"] [uri "/wp-login.php"] [unique_id "ZlZiSdOe9iyl76fMnBOdjAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
10dencehispahard SL
2024-05-08 06:01:07
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
Anonymous
2024-03-29 12:20:06
(2 years ago)
| XSS (Cross Site Scripting) attempt.
Hacking
SQL Injection
Web App Attack
🇪🇸
10dencehispahard SL
2024-03-27 07:00:25
(2 years ago)
Unauthorized login attempts [ BI-16635]
Brute-Force