๐บ๐ธ
TPI-Abuse
2026-08-28 22:34:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:34:43.892341 2026] [security2:error] [pid 9760:tid 9760] [client 107.173.36.35:48589] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nbcnewsradio.com"] [uri "/.git/config"] [unique_id "apINA1aeLQ65sEnPKkwwNwAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bigorre.org
2026-08-26 15:21:10
(6 days ago)
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-08-22 10:21:56
(1 week ago)
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-07-29 14:57:03
(1 month ago)
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-07-20 10:55:39
(1 month ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ฉ๐ช
C C
2026-02-25 14:31:50
(6 months ago)
Distributed proxy crawl wave (61 requests, 61 unique IPs, 28 ASNs in 590 sec); unauth. bot traffic w ...
show more
Distributed proxy crawl wave (61 requests, 61 unique IPs, 28 ASNs in 590 sec); unauth. bot traffic w/o verification; first observed at 2026-02-25T01:54:42+01:00
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 04:51:58
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 23:51:51.747158 2026] [security2:error] [pid 14106:tid 14106] [client 107.173.36.35:38325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.production"] [unique_id "aWsVZ83k-LpssvUl78GEugAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 17:57:18
(8 months ago)
(mod_security) mod_security (id:221260) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing. ...
show more
(mod_security) mod_security (id:221260) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 12:55:46.412246 2025] [security2:error] [pid 30284:tid 30634] [client 107.173.36.35:35289] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||www.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.com"] [uri "/cgi-bin/stats"] [unique_id "aVLAojko7uys3oTtjZtrHAAAANA"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-11 21:19:15
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 16:19:10.896206 2025] [security2:error] [pid 7499:tid 7499] [client 107.173.36.35:45741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.nbcnewsradio.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aROoTnCLKbnnShnRANHl5wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-01 15:53:47
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 11:53:41.546981 2025] [security2:error] [pid 27531:tid 27547] [client 107.173.36.35:58619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/.env.backup"] [unique_id "aQYtBX2WO2IkxYJ6zsIc4gAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 01:17:07
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing. ...
show more
(mod_security) mod_security (id:221260) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:17:00.237828 2025] [security2:error] [pid 404369:tid 404492] [client 107.173.36.35:52637] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||webdisk.kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kettlehill.net"] [uri "/cgi-bin/status"] [unique_id "aIV-DI1ApCwrT9-Kn8XG-QAAAJc"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-30 00:49:48
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing. ...
show more
(mod_security) mod_security (id:221260) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 20:49:40.224444 2025] [security2:error] [pid 3870856:tid 3870856] [client 107.173.36.35:44899] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||autodiscover.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.farmers123.com"] [uri "/cgi-bin/status/status.cgi"] [unique_id "aDkApOdoFwmy18Z82CcpDQAAABM"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-28 21:43:59
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing. ...
show more
(mod_security) mod_security (id:211190) triggered by 107.173.36.35 (107-173-36-35-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 28 16:43:00.053382 2025] [security2:error] [pid 14500:tid 14625] [client 107.173.36.35:33603] [client 107.173.36.35] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.kettlehill.com"] [uri "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp"] [unique_id "Z8It5LBju728IJklrll7UAAAAcg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-25 20:50:19
(1 year ago)
| A web attack returned code 200 (success).
Hacking
SQL Injection
Web App Attack