๐ณ๐ฑ
Roderic
2026-05-01 22:18:32
(1 month ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ฎ๐น
madaello
2026-03-06 16:10:59
(3 months ago)
[Fri Mar 06 17:10:59.326165 2026] [ssl:error] [pid 2134168:tid 2134168] [client 145.223.46.202:57627 ...
show more
[Fri Mar 06 17:10:59.326165 2026] [ssl:error] [pid 2134168:tid 2134168] [client 145.223.46.202:57627] AH02032: Hostname www.imperatrice.to.it provided via SNI and hostname 93.55.83.202 provided via HTTP have no compatible SSL setup for policy 'secure'
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-01 20:14:32
(3 months ago)
(mod_security) mod_security (id:211190) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 15:13:48.740756 2026] [security2:error] [pid 3623:tid 3746] [client 145.223.46.202:51431] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /wp-content/plugins/se-html5-album-audio-player/download_audio.php?file=/wp-content/uploads/../../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.com"] [uri "/wp-content/plugins/se-html5-album-audio-player/download_audio.php"] [unique_id "aaSd_F4WolzQRuAXATJ06QAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 11:04:34
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 06:04:30.194334 2026] [security2:error] [pid 2256:tid 2256] [client 145.223.46.202:36513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.dev"] [unique_id "aWtsvjm-8MmSfU0vx__-YQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 17:36:04
(5 months ago)
(mod_security) mod_security (id:211190) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 12:34:25.113197 2025] [security2:error] [pid 27842:tid 28106] [client 145.223.46.202:51769] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /wp-json/lp/v1/courses/archive-course?template_path=..%2F..%2F..%2Fetc%2Fpasswd&return_type=html"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.com"] [uri "/wp-json/lp/v1/courses/archive-course"] [unique_id "aVK7oaihNXaj9f6vryeNoQAAAFc"], referer: http://ftp.kettlehill.com/wp-json/lp/v1/courses/archive-course?template_path=..%2F..%2F..%2Fetc%2Fpasswd&return_type=html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 22:19:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 17:19:33.275166 2025] [security2:error] [pid 29073:tid 29073] [client 145.223.46.202:33777] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.farmers123.com"] [uri "/.svn/wc.db"] [unique_id "aS9l9ZYF-tUVicXFaB0MDQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 11:09:05
(7 months ago)
(mod_security) mod_security (id:212620) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:212620) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 06:09:01.094125 2025] [security2:error] [pid 32273:tid 32273] [client 145.223.46.202:47151] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /web/set_profiling?profile=0&collectors=<script>alert(document.domain)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "ftp.nbcnewsradio.com"] [uri "/web/set_profiling"] [unique_id "aRW8TfbT7wDXzzRwoz3dzAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-22 22:26:49
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 22 18:26:40.608782 2025] [security2:error] [pid 10110:tid 10110] [client 145.223.46.202:39795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.deandobkin.com"] [uri "/_.htaccess"] [unique_id "aNHNIAXMDTb1quD-JlrtjgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 01:46:02
(10 months ago)
(mod_security) mod_security (id:212620) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:212620) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:45:58.391701 2025] [security2:error] [pid 729657:tid 729699] [client 145.223.46.202:35221] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.kettlehill.net|F|2"] [data "Matched Data: <script found within REQUEST_URI: /error?msg=</script><script>alert(document.domain)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.kettlehill.net"] [uri "/error"] [unique_id "aIWE1hUVDjlJfvQpjEJYDAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 19:04:57
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 145.223.46.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 15:04:50.560169 2025] [security2:error] [pid 3255476:tid 3255476] [client 145.223.46.202:35877] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.farmers123.com"] [uri "/.svn/wc.db"] [unique_id "aDiv0hx3D_cZSaO1QvTH0QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-25 09:10:26
(1 year ago)
| SQL injection attempt.
Hacking
SQL Injection
Web App Attack
๐ต๐น
tiagozip
2024-02-07 23:10:48
(2 years ago)
open proxy
Open Proxy