🇺🇸
Blue Pumpkin
2026-08-27 05:15:42
(3 days ago)
154.6.128.46 - - [27/Aug/2026:05:12:22 +0000] "GET /component/comprofiler/userprofile/lllAX HTTP/1.1 ...
show more
154.6.128.46 - - [27/Aug/2026:05:12:22 +0000] "GET /component/comprofiler/userprofile/lllAX HTTP/1.1" 503 5787 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
🇨🇭
backslash
2026-06-26 13:03:04
(2 months ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
🇫🇷
bigorre.org
2026-06-01 09:58:11
(2 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
Anonymous
2026-01-01 05:22:00
(7 months ago)
[Thu Jan 01 06:22:00.235747 2026] [:error] [pid 91732:tid 91732] [client 154.6.128.46:52379] ModSecu ...
show more
[Thu Jan 01 06:22:00.235747 2026] [:error] [pid 91732:tid 91732] [client 154.6.128.46:52379] ModSecurity: Warning. Matched "Operator `Rx' with parameter `^\\(\\s*\\)\\s+\\{' against variable `REQUEST_HEADERS:Shellshock' (Value: `() { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "662"] [id "932170"] [rev ""] [msg "Remote Command Execution: Shellshock (CVE-2014-6271)"] [data "Matched Data: () { found within REQUEST_HEADERS:Shellshock: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd"] [severity "2"] [ver "OWASP_CRS/4.22.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-RCE"] [tag "capec/1000/152/248/88"] [uri "/"] [unique_id "176724492073.090861"] [ref "o0,4v189,74t:urlDecodeUnio0,4v2
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-12-29 17:18:59
(8 months ago)
(mod_security) mod_security (id:211070) triggered by 154.6.128.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211070) triggered by 154.6.128.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 12:08:01.511983 2025] [security2:error] [pid 19081:tid 19435] [client 154.6.128.46:44539] ModSecurity: Access denied with code 403 (phase 1). Pattern match "," at REQUEST_HEADERS:Transfer-Encoding. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "38"] [id "211070"] [rev "1"] [msg "COMODO WAF: HTTP Request Smuggling Attack.||kettlehill.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.kettlehill.com"] [uri "/tmui/login.jsp"] [unique_id "aVK1cdpjWKRP7e6xaCKdZwAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-13 09:41:46
(9 months ago)
(mod_security) mod_security (id:211190) triggered by 154.6.128.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 154.6.128.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:41:33.835488 2025] [security2:error] [pid 16821:tid 16821] [client 154.6.128.46:60517] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?c=../../../../../../../../etc/passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/"] [unique_id "aRWnzdtZrzA-vo0_o2ZFPwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-01 17:09:57
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 154.6.128.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 154.6.128.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 13:09:52.539891 2025] [security2:error] [pid 28909:tid 28916] [client 154.6.128.46:50577] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.com"] [uri "/www.key"] [unique_id "aN1gYMqzZow6xCeNbL7sJAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-05-29 19:59:23
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 15:59:19.852822 2025] [security2:error] [pid 3370574:tid 3370574] [client 154.6.128.46:45107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.farmers123.com"] [uri "/.env.development.local"] [unique_id "aDi8l6pGRIX7PdKizMFQZgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-02-27 14:36:11
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 154.6.128.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.128.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 09:33:52.716076 2025] [security2:error] [pid 27064:tid 27275] [client 154.6.128.46:46533] [client 154.6.128.46] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.staging.kettlehill.com"] [uri "/static../.git/config"] [unique_id "Z8B30GoEVIU_Tl3JLGhv5QAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-23 05:40:03
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack