πΊπΈ
TPI-Abuse
2026-06-01 01:48:22
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 21:47:46.918890 2026] [security2:error] [pid 11752:tid 12136] [client 104.238.38.247:37869] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.staging.kettlehill.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.staging.kettlehill.com"] [uri "/host.key"] [unique_id "ahzkwlK1j6eB9I0a-Y9KjAAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-01 20:25:55
(3 months ago)
(mod_security) mod_security (id:211190) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 15:25:47.352570 2026] [security2:error] [pid 32106:tid 32111] [client 104.238.38.247:59261] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?__kubio-site-edit-iframe-preview=1&__kubio-site-edit-iframe-classic-template=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.com"] [uri "/"] [unique_id "aaSgy8yHAVRioPijSO-DFQAAAMA"], referer: https://www.kettlehill.com/?__kubio-site-edit-iframe-preview=1&__kubio-site-edit-iframe-classic-template=../../../../../../../../etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-16 15:47:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 10:47:26.839217 2026] [security2:error] [pid 28760:tid 28760] [client 104.238.38.247:52727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.nbcnewsradio.com"] [uri "/wp-config.php.bak"] [unique_id "aWpdjq-02da1Ya1HIBBksAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-08 00:20:04
(6 months ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-02 23:43:21
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 18:43:14.933627 2025] [security2:error] [pid 4921:tid 4921] [client 104.238.38.247:37997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.farmers123.com"] [uri "/web.config"] [unique_id "aS95kqhc9vuqRww58G8TRQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-01 14:45:24
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 10:45:17.362184 2025] [security2:error] [pid 31390:tid 31399] [client 104.238.38.247:44659] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.com|F|2"] [data ".kettlehill.com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.com"] [uri "/ftp.kettlehill.com.sql"] [unique_id "aQYc_QTyOOjtViEU79ejCQAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-29 01:06:54
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 21:06:45.260957 2025] [security2:error] [pid 5278:tid 5278] [client 104.238.38.247:59275] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.nbcnewsradio.com"] [uri "/.env.nbcnewsradio"] [unique_id "aQFopU2UbxsWUgZ_YOMMaAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-01 01:40:47
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.238.38.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 21:40:43.533574 2025] [security2:error] [pid 4167172:tid 4167186] [client 104.238.38.247:37929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.net"] [uri "/_.htaccess"] [unique_id "aLT5m-ryNSoVQ-6incksHgAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
nowyouknow
2023-08-01 22:44:05
(2 years ago)
(From [email protected] ) Hi,
Would you be open to do an interview?
We are in ...
show more
(From [email protected] ) Hi,
Would you be open to do an interview?
We are interviewing business owners like you and give them the chance to share their story.
Would you like more information on how this works?
If Yes, please contact this email: [email protected]
We are looking forward to hear from you
Best,
Pam Glow
show less
Phishing
Web Spam
πΊπΈ
oncord
2023-07-31 15:19:21
(2 years ago)
Form spam
Web Spam
Anonymous
2023-07-03 00:49:05
(2 years ago)
Common attack or app scan event detected and blocked
Port Scan
Hacking
Web App Attack