🇺🇸
TPI-Abuse
2026-08-28 23:31:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:31:50.068204 2026] [security2:error] [pid 20180:tid 20180] [client 154.6.59.82:43683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.nbcnewsradio.com"] [uri "/.htaccess"] [unique_id "apIaZrhLajOgq6ZoZ9cOFQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-01 11:24:39
(6 months ago)
(mod_security) mod_security (id:211190) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 06:24:31.383164 2026] [security2:error] [pid 16720:tid 16854] [client 154.6.59.82:35639] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /wp-json/lp/v1/courses/archive-course?template_path=..%2F..%2F..%2Fetc%2Fpasswd&return_type=html"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/wp-json/lp/v1/courses/archive-course"] [unique_id "aX8373gN2ebRaezbXtJCtQAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-16 16:33:35
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 11:33:23.410007 2026] [security2:error] [pid 7986:tid 7986] [client 154.6.59.82:43279] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/.env.old"] [unique_id "aWpoU0aIjkqeyyRsJS8bKAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-02 23:38:24
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 18:38:20.871880 2025] [security2:error] [pid 27513:tid 27513] [client 154.6.59.82:52033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.farmers123.com"] [uri "/sftp-config.json"] [unique_id "aS94bOEJTLrv8N5BNgcsGgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-01 05:48:23
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 00:47:38.547472 2025] [security2:error] [pid 26090:tid 26450] [client 154.6.59.82:36489] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.com"] [uri "/mysql.sql"] [unique_id "aS0r-gqR0geke5MRGl4DOwAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
Erpelstolz
2025-11-25 12:52:01
(9 months ago)
VM 131: 154.6.59.82 - - [25/Nov/2025:13:51:55 +0100] "GET /...%5c...%5c...%5c...%5c...%5c...%5c...%5 ...
show more
VM 131: 154.6.59.82 - - [25/Nov/2025:13:51:55 +0100] "GET /...%5c...%5c...%5c...%5c...%5c...%5c...%5c...%5c...%5cwindows%5cwin.ini HTTP/1.1" 301 793
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-10-28 22:39:08
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 18:39:01.109560 2025] [security2:error] [pid 17336:tid 17336] [client 154.6.59.82:58273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nbcnewsradio.com"] [uri "/.env.nbcnewsradio"] [unique_id "aQFGBb1oq__YvBlLtXik5gAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-10 05:10:03
(10 months ago)
| Suspicious URL access.
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2025-10-01 15:03:48
(10 months ago)
(mod_security) mod_security (id:211190) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:03:40.732465 2025] [security2:error] [pid 9487:tid 9516] [client 154.6.59.82:44227] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?patron_only_image=../../../../../../../../../../etc/passwd&patreon_action=serve_patron_only_image"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.com"] [uri "/"] [unique_id "aN1CzEvyOqnYEaX7Ie4cDwAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-09-26 02:40:20
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 154.6.59.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 25 22:40:16.836665 2025] [security2:error] [pid 27469:tid 27469] [client 154.6.59.82:57329] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.deandobkin.com"] [uri "/.svn/wc.db"] [unique_id "aNX9EE4GTWTP9IN7kTv1aAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack