๐บ๐ธ
TPI-Abuse
2026-09-01 18:15:53
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:15:45.947570 2026] [security2:error] [pid 360759:tid 360856] [client 154.6.126.98:32799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.net"] [uri "/.env.kettlehill"] [unique_id "apcWUVJqyxcv70W9QdjHCAAABQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-18 03:22:55
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 06-22.154.6.126.98.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 06-22.154.6.126.98.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 06:24:12
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 01:24:02.985840 2026] [security2:error] [pid 16065:tid 16065] [client 154.6.126.98:56849] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/wp-config.php"] [unique_id "aWsrAvAC9a9PHcH2fo3t6wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 19:04:43
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:04:32.637539 2025] [security2:error] [pid 22842:tid 22991] [client 154.6.126.98:58809] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.net|F|2"] [data ".kettlehill.net.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.net"] [uri "/www.kettlehill.net.db"] [unique_id "aVLQwFKoonkfA7MmLZcLYwAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 10:36:11
(10 months ago)
(mod_security) mod_security (id:218420) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:218420) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 05:36:06.469883 2025] [security2:error] [pid 16393:tid 16393] [client 154.6.126.98:52473] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "ftp.nbcnewsradio.com"] [uri "/cgi-bin/php-cgi.exe"] [unique_id "aRW0lo8Kob68xnRZlfBfAAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2025-10-13 03:21:30
(11 months ago)
query: rest_route=/wqc/v1/query
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-27 00:09:53
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:09:41.700034 2025] [security2:error] [pid 146057:tid 146146] [client 154.6.126.98:54509] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.com"] [uri "/vpns/cfg/smb.conf"] [unique_id "aIVuRQtdUXc7wYRdaLO2PwAAAZQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 16:20:50
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 12:20:38.059784 2025] [security2:error] [pid 2956908:tid 2956908] [client 154.6.126.98:34907] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.farmers123.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.farmers123.com"] [uri "/ftp.db"] [unique_id "aDiJViRYFKQ3XqbBsEqGQQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-04 15:10:02
(1 year ago)
| A web attack returned code 200 (success).
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-19 05:24:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 154.6.126.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 19 01:24:36.345354 2025] [security2:error] [pid 22650:tid 22658] [client 154.6.126.98:53355] [client 154.6.126.98] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.blog.spinningdesigns.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blog.spinningdesigns.com"] [uri "/admin/logs/error.log"] [unique_id "aAMzlMLYwl69KqC_78iZ4wAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack