๐บ๐ธ
TPI-Abuse
2026-09-01 17:03:57
(1 day ago)
(mod_security) mod_security (id:211190) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:03:49.904283 2026] [security2:error] [pid 1188365:tid 1188443] [client 104.239.73.33:50301] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?p=%3C%3Fxml+version%3D%221.0%22%3F%3E%3C%21DOCTYPE+foo+%5B%3C%21ENTITY+xxe+SYSTEM+%22file%3A%2F%2F%2Fetc%2Fpasswd%22%3E%5D%3E%3Cfoo%3E%26xxe%3B%3C%2Ffoo%3E"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.com"] [uri "/"] [unique_id "apcFdXaScgMvQoSgVBotDQAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
HeliJP
2026-08-22 14:45:39
(1 week ago)
2026-08-22T14:19:05Z - Recognized attacks\bad behavior from IP address 104.239.73.33 on port 443\80 ...
show more
2026-08-22T14:19:05Z - Recognized attacks\bad behavior from IP address 104.239.73.33 on port 443\80 (3 daily hits): client denied by server configuration
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-08-10 09:17:20
(3 weeks ago)
IM360 WAF: Dangerous PHP functions in REQUEST_URI MV:/wp-admin/admin-ajax.php?+config-create+/&/<?=b ...
show more
IM360 WAF: Dangerous PHP functions in REQUEST_URI MV:/wp-admin/admin-ajax.php?+config-create+/&/<?=base64_decode($_GET[0])?>+/tmp/3Hiabi1UEyOyFuMi1AKpuU8ElqR.php
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 05:55:44
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 01:55:37.512507 2026] [security2:error] [pid 1354:tid 1354] [client 104.239.73.33:50455] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kingstoneproperties.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kingstoneproperties.com"] [uri "/[email protected] "] [unique_id "ajI22YRuWUp2Zz7F9DvfCgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 02:54:50
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:54:42.221619 2026] [security2:error] [pid 7577:tid 7686] [client 104.239.73.33:57827] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.net"] [uri "/server.key"] [unique_id "ahz0co6nP6TlQzUBlJvaMAAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 21:22:15
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 17:22:11.815785 2026] [security2:error] [pid 153393:tid 153393] [client 104.239.73.33:59187] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.nbcnewsradio.com|F|2"] [data ".old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.nbcnewsradio.com"] [uri "/.ssh/known_hosts.old"] [unique_id "adbHA3DsXuZYdqHTxS8v0gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-07 17:34:11
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 07 12:34:04.269541 2026] [security2:error] [pid 527:tid 527] [client 104.239.73.33:53471] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nbcnewsradio.com|F|2"] [data ".com.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nbcnewsradio.com"] [uri "/nbcnewsradio.com.db"] [unique_id "aYd3jOe9RziBqgaMX0eyWwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 11:24:54
(7 months ago)
(mod_security) mod_security (id:212750) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212750) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 06:24:46.211448 2026] [security2:error] [pid 16722:tid 16905] [client 104.239.73.33:39105] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||mail.kettlehill.com|F|2"] [data "Matched Data: onerror= found within REQUEST_URI: /?spai_vjs=</script><img src=1 onerror=alert(document.domain)>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "mail.kettlehill.com"] [uri "/"] [unique_id "aX83_syMbG6v0xSDvGJU4QAAAtM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-03 02:52:28
(9 months ago)
(mod_security) mod_security (id:212750) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212750) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 21:52:21.416893 2025] [security2:error] [pid 12301:tid 12301] [client 104.239.73.33:42227] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||www.farmers123.com:80|F|2"] [data "Matched Data: onload= found within REQUEST_URI: /control/stream?contentid='\\x5c\\x22><svg/onload=alert(/xss/)>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.farmers123.com"] [uri "/control/stream"] [unique_id "aS-l5amA-rgTOFQShcgA6gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 06:19:29
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:19:26.760911 2025] [security2:error] [pid 8488:tid 8577] [client 104.239.73.33:47061] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.com"] [uri "/.env.bak"] [unique_id "aS0zbtZHHfu_5jcVG6pmUwAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 14:23:12
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 09:23:09.093635 2025] [security2:error] [pid 31088:tid 31088] [client 104.239.73.33:58703] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nbcnewsradio.com"] [uri "/example.htaccess"] [unique_id "aRSYTeX6EPjZv8Xs3bLVHQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
RoboSOC
2025-10-15 00:01:52
(10 months ago)
Microsoft Windows win.ini Access Attempt Detected , PTR: PTR record not found
Hacking
๐บ๐ธ
TPI-Abuse
2025-10-01 15:14:54
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:14:45.633953 2025] [security2:error] [pid 12475:tid 12486] [client 104.239.73.33:60689] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.kettlehill.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.kettlehill.net"] [uri "/..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\windows\\\\win.ini"] [unique_id "aN1FZWCKjmgjI9kURFKrpQAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-08-18 09:38:06
(1 year ago)
WP probing for vulnerabilities
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-08-01 06:49:04
(1 year ago)
(mod_security) mod_security (id:212620) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:212620) triggered by 104.239.73.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 02:48:47.273282 2025] [security2:error] [pid 3331447:tid 3331462] [client 104.239.73.33:57791] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.kettlehill.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /does_not_exist\\x22\\x22><script>alert(document.domain)</script><imgsrc=x"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.kettlehill.com"] [uri "/does_not_exist\\"\\"><script>alert(document.domain)</script><img src=x"] [unique_id "aIxjT1SZjg6lcpTf51ZlcAAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack