|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240950) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240950) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 16:05:19.564092 2025] [security2:error] [pid 21770:tid 21775] [client 161.123.154.28:37563] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||ftp.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ftp.kettlehill.com"] [uri "/_users/org.couchdb.user:poc"] [unique_id "aVLtD-1IUNfWG5lsn0HE6AAAAYI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:51:59.950272 2025] [security2:error] [pid 28670:tid 28670] [client 161.123.154.28:43263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/.env.backup"] [unique_id "aRWqP_RXlpEDsAGmXRxN6wAAAAE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π©πͺ
ps-center
|
|
SS1: Web Attack GET /.ssh/id_rsa
|
Web Spam
Hacking
Bad Web Bot
Web App Attack
|
|
|
π©πͺ
Alejandro Docasar
|
|
|
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:211190) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211190) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 26 22:37:01.639966 2024] [security2:error] [pid 13008:tid 13130] [client 161.123.154.28:60341] [client 161.123.154.28] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?filename=../../../../../../etc/passwd&mphb_action=download"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.com"] [uri "/"] [unique_id "Zx2nTZ3t9n-ZbyO007y0hQAAAVc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 14:42:53.970230 2024] [security2:error] [pid 21476:tid 21476] [client 161.123.154.28:46759] [client 161.123.154.28] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.stdavids-media.com"] [uri "/static../.git/config"] [unique_id "ZtdYrSxnhru-CdrABhqYfgAAABQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:221260) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 27 16:23:55.576978 2024] [security2:error] [pid 23119:tid 23145] [client 161.123.154.28:32907] [client 161.123.154.28] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||staging.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/cgi-bin/status/status.cgi"] [unique_id "ZqVXW9C5xPF3XKcxXkCllAAAAY8"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π©πͺ
ps-center
|
|
SS1: Web Attack GET /resource/file%3a///etc/passwd/
|
Web Spam
Hacking
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240950) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240950) triggered by 161.123.154.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 14 21:50:11.568395 2024] [security2:error] [pid 5014:tid 47952275678976] [client 161.123.154.28:43393] [client 161.123.154.28] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||www.staging.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.staging.kettlehill.com"] [uri "/jira/secure/QueryComponentRendererValue!Default.jspa"] [unique_id "ZkQU0-DW24d8EzRQX0REfwAAAEk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πͺπΈ
10dencehispahard SL
|
|
Unauthorized login attempts []
|
Brute-Force
|
|
|
πͺπΈ
10dencehispahard SL
|
|
Web Attack
|
DDoS Attack
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
|
Brute-Force
SSH
|
|
|
Anonymous
|
|
| XSS (Cross Site Scripting) attempt.
|
Hacking
SQL Injection
Web App Attack
|
|
|
πͺπΈ
10dencehispahard SL
|
|
Unauthorized login attempts [ BI-16635]
|
Brute-Force
|
|
|
πͺπΈ
10dencehispahard SL
|
|
WP scan
|
Web App Attack
|
|