๐บ๐ธ
TPI-Abuse
2026-09-01 18:13:02
(2 hours ago)
(mod_security) mod_security (id:211190) triggered by 119.12.198.232 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 119.12.198.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:12:43.733705 2026] [security2:error] [pid 294246:tid 295297] [client 119.12.198.232:45601] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?p=3232&wp_automatic=download&link=file:///etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.com"] [uri "/"] [unique_id "apcVm3HIocTMXIhvatcObAAAAgI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-08-29 23:42:00
(2 days ago)
block ruleset A83E80CC113635A4EF3A24679E16A44DF84CAB37
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-01 20:16:16
(6 months ago)
(mod_security) mod_security (id:220150) triggered by 119.12.198.232 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:220150) triggered by 119.12.198.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 15:16:12.304400 2026] [security2:error] [pid 32106:tid 32129] [client 119.12.198.232:39543] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:bwg_tag_id_bwg_thumbnails_0[]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||www.staging.kettlehill.com|F|2"] [data ")\\x22unionselect1,2,3,4,5,6,7,concat(md5(999999999),0x2c,8),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--g"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.staging.kettlehill.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aaSejMyHAVRioPijSO92-AAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 05:54:29
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 119.12.198.232 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 119.12.198.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 00:53:35.267010 2025] [security2:error] [pid 26090:tid 26456] [client 119.12.198.232:37093] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.kettlehill.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.kettlehill.com"] [uri "/admin/logs/error.log"] [unique_id "aS0tXwqR0geke5MRGl4JjwAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Shaik Sai Meera
2025-11-29 00:50:39
(9 months ago)
IM360 WAF: Request indicates a Headless browser
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-01 15:33:20
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 119.12.198.232 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 119.12.198.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 11:33:14.336067 2025] [security2:error] [pid 8590:tid 8612] [client 119.12.198.232:43689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kettlehill.com"] [uri "/sample.htaccess"] [unique_id "aQYoOnl6EaMmM6sQysSptwAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 01:37:28
(1 year ago)
(mod_security) mod_security (id:210580) triggered by 119.12.198.232 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210580) triggered by 119.12.198.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 21:37:21.024026 2025] [security2:error] [pid 4167172:tid 4167186] [client 119.12.198.232:37099] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:local-destination-id. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.kettlehill.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:local-destination-id: /etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.kettlehill.com"] [uri "/wp-admin/admin-post.php"] [unique_id "aLT40eryNSoVQ-6inckq-gAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-08-18 09:38:51
(1 year ago)
WP probing for vulnerabilities
Hacking
Exploited Host
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-12 20:10:38
(1 year ago)
Fail2ban picked up 119.12.198.232 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-11 20:07:01
(1 year ago)
Fail2ban picked up 119.12.198.232 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-09 20:23:17
(1 year ago)
Fail2ban picked up 119.12.198.232 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-08 20:20:14
(1 year ago)
Fail2ban picked up 119.12.198.232 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-07 20:17:05
(1 year ago)
Fail2ban picked up 119.12.198.232 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-06 20:14:17
(1 year ago)
Fail2ban picked up 119.12.198.232 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-05 20:11:07
(1 year ago)
Fail2ban picked up 119.12.198.232 attacking nginx
Web App Attack