๐ฉ๐ช
C C
2026-08-08 23:42:45
(1 month ago)
Distributed scraping attack: 1469 req from 1403 rotating proxy IPs, waves of up to 150 req in 291s o ...
show more
Distributed scraping attack: 1469 req from 1403 rotating proxy IPs, waves of up to 150 req in 291s on a single URL | this IP: 1 req, 1 blocked | host appears compromised (residential proxy botnet)
show less
Open Proxy
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 18:01:18
(8 months ago)
(mod_security) mod_security (id:221260) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 12:55:39.936413 2025] [security2:error] [pid 30292:tid 30597] [client 104.238.38.173:33701] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||webmail.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.com"] [uri "/debug.cgi"] [unique_id "aVLAm4Gwzh_8AlcRvOiMbgAAAQ4"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 09:46:12
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:46:08.928897 2025] [security2:error] [pid 25103:tid 25103] [client 104.238.38.173:35977] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/assets../.git/config"] [unique_id "aRWo4DG3mAXX-Qf3dr_pewAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 02:08:36
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 22:08:31.302774 2025] [security2:error] [pid 729657:tid 729714] [client 104.238.38.173:48833] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kettlehill.com"] [uri "/events../.git/config"] [unique_id "aIWKHxUVDjlJfvQpjEJhdgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 16:38:32
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 12:38:22.122777 2025] [security2:error] [pid 2973353:tid 2973353] [client 104.238.38.173:55299] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||www.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.farmers123.com"] [uri "/"] [unique_id "aDiNfmxTEZtnJnZCXC5reQAAAB4"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-27 14:13:15
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 09:12:56.685948 2025] [security2:error] [pid 13564:tid 13619] [client 104.238.38.173:38401] [client 104.238.38.173] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||autodiscover.staging.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.staging.kettlehill.com"] [uri "/"] [unique_id "Z8By6B1H7NLw7pprsrFQzAAAAUs"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2024-05-02 05:36:54
(2 years ago)
Form spam
Web Spam
๐ฆ๐บ
oncord
2024-04-30 16:50:03
(2 years ago)
Form spam
Web Spam
๐จ๐ญ
backslash
2024-04-29 05:52:39
(2 years ago)
Web Spam
๐ฆ๐บ
MAGIC
2024-04-28 03:09:55
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฆ๐บ
oncord
2024-04-26 08:03:00
(2 years ago)
Form spam
Web Spam
๐บ๐ธ
nowyouknow
2024-04-26 05:52:31
(2 years ago)
(From [email protected] ) Are you okay running your business without a lot of funds? This mi ...
show more
(From [email protected] ) Are you okay running your business without a lot of funds? This might impede growth and postpone returns on your business.
Now you have the Opportunity to get Financing for your Business and Projects without pressure and any burden of repayment as our first interest lies in fostering the growth of your business and projects, allowing you to realize your desired business goals and dreams.
Take advantage of our Financing opportunity and receive funding for your business and projects within days, and a generous number of years to the loan term period, providing you ample time to grow and reach your business goals.
Get in touch with us at:
+852 3008 8373,
or email us at:
[email protected]
Unsubscribe here if you don't want to get these great offers: https://docs.google.com/forms/d/e/1FAIpQLSdx-LI-ETiB-g37_ijIRHfBNhu__c-Go1dyOyZ_zU_pgeYTEg/viewform?usp=sf_link
1673 Cecil Street, Jamestown, New York, USA, 60606
show less
Phishing
Web Spam
๐บ๐ธ
TPI-Abuse
2023-11-19 12:20:25
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.238.38.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 19 07:20:20.333458 2023] [security2:error] [pid 24235:tid 47138625058560] [client 104.238.38.173:55215] [client 104.238.38.173] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.com"] [uri "/ftp.db"] [unique_id "ZVn9hCWJZD9BO6qPxtgZDwAAAM0"], referer: http://ftp.kettlehill.com/ftp.db
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ChamberofCommerce.com
2023-11-06 02:03:00
(2 years ago)
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested ...
show more
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested Before Block:226
show less
Bad Web Bot
๐บ๐ธ
ChamberofCommerce.com
2023-11-02 04:53:37
(2 years ago)
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested ...
show more
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested Before Block:226
show less
Bad Web Bot