๐จ๐ญ
backslash
2026-06-16 11:42:11
(1 day ago)
block ruleset 7B8FD6B12C4E12B6F0DAE02E53C0597FBEDDF5BC
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-03 13:48:11
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 03 09:47:25.714038 2025] [security2:error] [pid 13360:tid 13379] [client 104.232.211.112:58421] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.staging.kettlehill.com"] [uri "/web.config"] [unique_id "aGaJ7aUco3AoK6nd7NFEjwAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 16:51:57
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 12:51:52.206399 2025] [security2:error] [pid 3020133:tid 3020133] [client 104.232.211.112:44909] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.farmers123.com"] [uri "/js../.git/config"] [unique_id "aDiQqA4z2i7hiVXi_vmmuwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-04 11:34:41
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 04 07:34:33.776259 2024] [security2:error] [pid 23243:tid 23243] [client 104.232.211.112:42009] [client 104.232.211.112] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||stdavids-media.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_pro_desk&include_file=../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stdavids-media.com"] [uri "/index.php"] [unique_id "ZthFyaHEOEhXNIdlAFT1QAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-01 01:55:13
(1 year ago)
(mod_security) mod_security (id:210410) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210410) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 31 21:51:22.110158 2024] [security2:error] [pid 3087700:tid 3087751] [client 104.232.211.112:47321] [client 104.232.211.112] ModSecurity: Access denied with code 403 (phase 2). Found 1 byte(s) in ARGS:skin outside range: 1-255. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "95"] [id "210410"] [rev "4"] [msg "COMODO WAF: Invalid character in request||staging.kettlehill.com|F|3"] [data "ARGS:skin=../../../../../../../../../opt/zimbra/conf/localconfig.xml\\x00"] [severity "ERROR"] [tag "CWAF"] [tag "Protocol"] [hostname "staging.kettlehill.com"] [uri "/res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx TemplateMsg.js.zgz"] [unique_id "ZtPImtyH84duF-C5mXVGDgAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-28 12:01:26
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-06-27 06:58:33
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 27 02:56:55.218726 2024] [security2:error] [pid 31724:tid 47386278582016] [client 104.232.211.112:48949] [client 104.232.211.112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kettlehill.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "Zn0NN-1YCwZvqwSPAshRswAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:00:43
(2 years ago)
Unauthorized login attempts []
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:11:49
(2 years ago)
Web Attack
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-01 16:06:08
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 01 12:05:18.630518 2024] [security2:error] [pid 12232:tid 47912195839744] [client 104.232.211.112:33429] [client 104.232.211.112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.net|F|2"] [data ".kettlehill.net.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.net"] [uri "/www.kettlehill.net.db"] [unique_id "ZgrbPt4NDFRb0FgzlOyACQAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-03-27 07:00:25
(2 years ago)
Unauthorized login attempts [ BI-16635]
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-03-27 06:42:47
(2 years ago)
WP scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-26 13:26:52
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 26 08:26:34.188194 2024] [security2:error] [pid 9795] [client 104.232.211.112:38623] [client 104.232.211.112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||stdavids-media.com|F|2"] [data ".com_db.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stdavids-media.com"] [uri "/stdavids-media.com_db.sql"] [unique_id "ZbOzCrZMtTfGPyA65Bkj0wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-06 03:41:20
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 104.232.211.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 05 22:40:24.463425 2023] [security2:error] [pid 10471:tid 47074303125248] [client 104.232.211.112:44673] [client 104.232.211.112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kettlehill.net"] [uri "/.env.www"] [unique_id "ZW_tKBWEYrhiHRh1KPYSxAAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-11-26 18:30:05
(2 years ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack