Anonymous
2026-09-10 11:10:22
(51 minutes ago)
| Common web attack.
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-06-01 02:13:38
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:13:31.505303 2026] [security2:error] [pid 7577:tid 7688] [client 104.239.7.99:53391] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.com"] [uri "/\\\\windows/win.ini"] [unique_id "ahzqy46nP6TlQzUBlJvRgAAAAMs"], referer: http://www.kettlehill.com/%5Cwindows/win.ini
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-08 21:06:23
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 17:06:18.105392 2026] [security2:error] [pid 128858:tid 128858] [client 104.239.7.99:45989] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\windows\\\\win.ini"] [unique_id "adbDSm3jk7VpQFXdBGSfygAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-01 12:04:26
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 07:04:22.381039 2026] [security2:error] [pid 483:tid 649] [client 104.239.7.99:51347] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kettlehill.com"] [uri "/_.htaccess"] [unique_id "aX9BRgMxl-cQ0UzvOvSTHQAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-16 16:27:50
(7 months ago)
(mod_security) mod_security (id:221260) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:221260) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 11:27:44.288719 2026] [security2:error] [pid 1623:tid 1623] [client 104.239.7.99:34619] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpanel.nbcnewsradio.com:443|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nbcnewsradio.com"] [uri "/debug.cgi"] [unique_id "aWpnALAx9IHk3Ae7u4sE3AAAACI"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raspi4
2025-12-31 15:30:27
(8 months ago)
Fail2Ban Ban Triggered
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 21:47:34
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 16:47:30.319326 2025] [security2:error] [pid 17288:tid 17288] [client 104.239.7.99:43807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.farmers123.com"] [uri "/.svn/wc.db"] [unique_id "aS9ecjPOcpEXuhW_28TIhgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-29 13:13:58
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 29 09:13:41.820239 2025] [security2:error] [pid 11317:tid 11317] [client 104.239.7.99:49853] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.davispickering.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.davispickering.com"] [uri "/www.davispickering.com/errors.log"] [unique_id "aQITBbjoUdg2lv_VRtl1dAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-28 19:41:51
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 15:41:43.001703 2025] [security2:error] [pid 24562:tid 24562] [client 104.239.7.99:40763] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ftp.nbcnewsradio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ftp.nbcnewsradio.com"] [uri "/sse"] [unique_id "aQEcduONvNXZnhqjC-A-IgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-01 14:50:31
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 10:50:25.024601 2025] [security2:error] [pid 9487:tid 9522] [client 104.239.7.99:60015] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.com|F|2"] [data ".old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.com"] [uri "/.ssh/known_hosts.old"] [unique_id "aN0_sUvyOqnYEaX7Ie4SKAAAAM0"], referer: http://www.kettlehill.com/.ssh/known_hosts.old
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-29 04:30:01
(11 months ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2025-08-05 20:11:19
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 05 16:11:13.536402 2025] [security2:error] [pid 26724:tid 26724] [client 104.239.7.99:41447] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/storage/logs/laravel.log"] [unique_id "aJJlYVpFhR9LCib-06b06AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-08-01 06:39:22
(1 year ago)
(mod_security) mod_security (id:220150) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:220150) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 02:39:13.236540 2025] [security2:error] [pid 3331447:tid 3331472] [client 104.239.7.99:42793] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:s. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||mail.kettlehill.com|F|2"] [data "9999')unionselect111,222,(select(concat(0x44617461626173653a20,database()))),4444,5---"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mail.kettlehill.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aIxhEVSZjg6lcpTf51ZUiAAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-06-01 08:03:56
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.7.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 04:03:47.520718 2025] [security2:error] [pid 2636838:tid 2636924] [client 104.239.7.99:44791] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.kettlehill.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.kettlehill.net"] [uri "/header.php.bak"] [unique_id "aDwJYzvwu3ccjH5oiKEiHwAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack