๐จ๐ญ
backslash
2026-03-01 03:21:22
(7 months ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-27 03:18:41
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 22:18:34.512764 2026] [security2:error] [pid 25623:tid 25649] [client 161.123.151.239:40435] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.kettlehill.com|F|2"] [data ".com.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.kettlehill.com"] [uri "/kettlehill.com.db"] [unique_id "aXguiknFQpvwgxC6L2HskAAAAZc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-31 11:29:23
(9 months ago)
[Wed Dec 31 12:29:23.008056 2025] [:error] [pid 3947403:tid 3947403] [client 161.123.151.239:58485] ...
show more
[Wed Dec 31 12:29:23.008056 2025] [:error] [pid 3947403:tid 3947403] [client 161.123.151.239:58485] ModSecurity: Warning. Matched "Operator `Within' with parameter `.ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll (418 characters omitted)' against variable `TX:EXTENSION' (Value: `.ini/' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1039"] [id "920440"] [rev ""] [msg "URL file extension is restricted by policy"] [data ".ini"] [severity "2"] [ver "OWASP_CRS/4.22.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [uri "/...\\...\\...\\...\\...\\...\\...\\...\\...\\windows\\win.ini
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 09:40:26
(10 months ago)
(mod_security) mod_security (id:218420) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:218420) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:40:22.866211 2025] [security2:error] [pid 22735:tid 22735] [client 161.123.151.239:52679] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "ftp.nbcnewsradio.com"] [uri "/php-cgi/php-cgi.exe"] [unique_id "aRWnhm-j05WT4Dh0Ay-LGAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2025-10-13 03:18:17
(11 months ago)
option=com_zhbaidumap&no_html=1&format=raw&task=getPlacemarkDetails
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-26 23:24:28
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:221260) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 19:24:07.919000 2025] [security2:error] [pid 26224:tid 26560] [client 161.123.151.239:53489] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||whm.staging.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.staging.kettlehill.com"] [uri "/cgi-bin/test-cgi"] [unique_id "aIVjl_TFOSR3bM1_Ra8R9gAAAMc"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 21:39:36
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 17:39:29.904265 2025] [security2:error] [pid 3572092:tid 3572092] [client 161.123.151.239:48485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.farmers123.com"] [uri "/.env.autodiscover"] [unique_id "aDjUERHQot9zTKN3P3bbpgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-19 03:11:35
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 18 23:10:17.659526 2025] [security2:error] [pid 14944:tid 14959] [client 161.123.151.239:56829] [client 161.123.151.239] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.spinningdesigns.com"] [uri "/js../.git/config"] [unique_id "aAMUGalkjOMtrQ4IEmniywAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-28 21:43:39
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 161.123.151.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 28 16:42:58.783075 2025] [security2:error] [pid 14500:tid 14619] [client 161.123.151.239:48753] [client 161.123.151.239] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/f5-release"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.com"] [uri "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp"] [unique_id "Z8It4rBju728IJklrll7PAAAAcI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-15 02:41:10
(1 year ago)
| A web attack returned code 200 (success).
Hacking
SQL Injection
Web App Attack