Anonymous
2026-09-10 17:09:46
(2 hours ago)
104.238.20.4 - - [10/Sep/2026:19:09:45 +0200] "GET /%5cwindows/win.ini HTTP/1.1" 403 5559 "http://ww ...
show more
104.238.20.4 - - [10/Sep/2026:19:09:45 +0200] "GET /%5cwindows/win.ini HTTP/1.1" 403 5559 "http://www.solgar.nl/%5Cwindows/win.ini" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36"
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-02-01 11:42:36
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 06:37:40.850113 2026] [security2:error] [pid 483:tid 662] [client 104.238.20.4:55193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/wp-config.php.old"] [unique_id "aX87BAMxl-cQ0UzvOvSBQQAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-14 13:47:56
(7 months ago)
(mod_security) mod_security (id:212620) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 08:47:49.485227 2026] [security2:error] [pid 29070:tid 29070] [client 104.238.20.4:34967] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||mail.nbcnewsradio.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /?zpyisjgm=<script>alert(\\x22xss\\x22);</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "mail.nbcnewsradio.com"] [uri "/"] [unique_id "aWeehQV1BTxQfZGzRfVliQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-01 05:46:02
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 00:45:49.244892 2025] [security2:error] [pid 31256:tid 31275] [client 104.238.20.4:51365] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.kettlehill.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.kettlehill.com"] [uri "/localhost.sql"] [unique_id "aS0rjW28JkE_f6YcP87r9QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-29 02:48:37
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 22:48:30.038684 2025] [security2:error] [pid 29301:tid 29301] [client 104.238.20.4:48165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.bak"] [unique_id "aQGAfqkx43EFbwOtSSwZ4wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-01 15:46:28
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:46:20.596017 2025] [security2:error] [pid 30111:tid 30190] [client 104.238.20.4:34181] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.kettlehill.com|F|2"] [data ".kettlehill.kettlehill.com.key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.kettlehill.com"] [uri "/www.kettlehill.kettlehill.com.key"] [unique_id "aN1MzBH4YjaIRtXIcLB98QAAAhQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-26 04:44:36
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 26 00:44:30.937823 2025] [security2:error] [pid 14142:tid 14142] [client 104.238.20.4:39347] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.deandobkin.com"] [uri "/.env.stage"] [unique_id "aNYaLukeOziYRwh0HSs7igAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2025-08-28 17:10:02
(1 year ago)
IP was involved in L7 DDoS attack.
DDoS Attack
🇺🇸
TPI-Abuse
2025-08-01 07:59:58
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 03:59:54.183550 2025] [security2:error] [pid 3712160:tid 3712194] [client 104.238.20.4:53409] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.net"] [uri "/wp-login.php.bak"] [unique_id "aIxz-tc_-1Eg368SpPiHYQAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-02 07:40:04
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2025-06-01 13:54:41
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 09:54:36.771637 2025] [security2:error] [pid 2868724:tid 2868724] [client 104.238.20.4:39217] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nbcnewsradio.com|F|2"] [data ".example.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nbcnewsradio.com"] [uri "/.example.com"] [unique_id "aDxbnGddnLSQRlZuiudk5QAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-06-01 06:08:54
(1 year ago)
(mod_security) mod_security (id:218420) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:218420) triggered by 104.238.20.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 02:08:47.756756 2025] [security2:error] [pid 2636838:tid 2636909] [client 104.238.20.4:50443] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mail.kettlehill.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mail.kettlehill.com"] [uri "/php-cgi/php.exe"] [unique_id "aDvubzvwu3ccjH5oiKEEjAAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack