Anonymous
2026-05-22 13:46:12
(2 weeks ago)
LH-Watcher: FAKE_ID [Fake Googlebot]
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-17 01:11:08
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 20:10:59.756318 2026] [security2:error] [pid 27828:tid 27828] [client 104.239.35.241:55839] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nbcnewsradio.com"] [uri "/.env.old"] [unique_id "aWrhoywec3lbvpNbahI9PAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 19:44:05
(5 months ago)
(mod_security) mod_security (id:221260) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:43:50.721093 2025] [security2:error] [pid 29977:tid 30003] [client 104.239.35.241:34811] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||webmail.kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.net"] [uri "/cgi-bin/test-cgi"] [unique_id "aVLZ9jWelXmsIDHwJWbmrAAAAZg"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 06:16:41
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:16:35.222503 2025] [security2:error] [pid 27471:tid 27497] [client 104.239.35.241:39579] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.kettlehill.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.kettlehill.net"] [uri "/sse"] [unique_id "aS0yw3LXOKC0tXS7y0kl8wAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-29 01:22:45
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 21:22:38.221829 2025] [security2:error] [pid 19737:tid 19737] [client 104.239.35.241:43785] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nbcnewsradio.com"] [uri "/mail.nbcnewsradio.com/error.log"] [unique_id "aQFsXoxzT-3TMrfEppKZdQAAAFw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 01:09:29
(10 months ago)
(mod_security) mod_security (id:211190) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:09:24.961589 2025] [security2:error] [pid 404367:tid 404519] [client 104.239.35.241:47475] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||staging.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?target=db_sql.php%253f/../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/index.php"] [unique_id "aIV8RAU3F-1fMbOT39mrPgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 23:52:34
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.239.35.241 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 19:52:28.488146 2025] [security2:error] [pid 3793645:tid 3793645] [client 104.239.35.241:44657] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.farmers123.com"] [uri "/.env.dev.local"] [unique_id "aDjzPI6OMJrzxeQKkmiQuAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-29 14:46:02
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
Anonymous
2025-03-29 10:58:22
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
Anonymous
2025-03-25 04:58:09
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
Anonymous
2025-02-27 17:30:07
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐ธ๐ฌ
oncord
2024-10-07 00:57:30
(1 year ago)
Form spam
Web Spam
๐บ๐ธ
nowyouknow
2024-09-28 09:17:48
(1 year ago)
(From [email protected] ) Just as you've received this message, we can send your message to mil ...
show more
(From [email protected] ) Just as you've received this message, we can send your message to millions of readers successfully!
Unleash the potential of bulk contact form submissions with our services. Reach millions of website owners every day and experience immediate results. We can submit up to 1 million messages per day, driving:
+ Targeted Visitors
+ Qualified Leads
+ New Customers
+ Increased Purchases
Make use of our service now! Starting from $9.
** Check out: https://bit.ly/bulksubmit
If you want to unsubscribe from this list and all future mails, please fill the form at https://bit.ly/unsubscribethat
68 Thompsons Lane, Melsonby, NA, Great Britain, Dl10 2ln
show less
Phishing
Web Spam
Anonymous
2024-09-27 05:46:55
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
nowyouknow
2024-09-20 11:15:03
(1 year ago)
(From [email protected] ) Claim your $32,220 tax credit with SETC PROS before it expires in Ap ...
show more
(From [email protected] ) Claim your $32,220 tax credit with SETC PROS before it expires in April 2025. Secure your savings now! The Self-Employed Tax Credit (SETC) supports those impacted by COVID-19, including Sick and Family Leave credits under the FFCRA.
++ Get it now: https://bit.ly/setcpros
You can unsubscribe by sending an email with subject "Unsubscribe" to [email protected]
Jan De Beyerstraat 93, Maastricht, LI, Netherlands, 6217 Gn
show less
Phishing
Web Spam