๐บ๐ธ
TPI-Abuse
2026-06-01 02:53:24
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 161.123.209.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 161.123.209.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:53:18.265768 2026] [security2:error] [pid 12707:tid 12729] [client 161.123.209.124:36155] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.com"] [uri "/error.log"] [unique_id "ahz0Hvr1zQOtbkd9viU2LgAAABI"], referer: http://www.kettlehill.com/error.log
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-05-01 12:23:23
(3 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ช๐ธ
10dencehispahard SL
2025-08-18 09:40:10
(1 year ago)
WP probing for vulnerabilities
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-07-01 06:53:56
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 161.123.209.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 161.123.209.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 01 02:53:51.606152 2025] [security2:error] [pid 30219:tid 30231] [client 161.123.209.124:50163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/.htpasswd"] [unique_id "aGOF__tpdo0a25O2Z1bdiAAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-01 02:52:03
(1 year ago)
(mod_security) mod_security (id:210580) triggered by 161.123.209.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210580) triggered by 161.123.209.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 30 22:51:41.296598 2025] [security2:error] [pid 10928:tid 11077] [client 161.123.209.124:57543] [client 161.123.209.124] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:local-destination-id. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||mail.kettlehill.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:local-destination-id: /etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "mail.kettlehill.com"] [uri "/wp-admin/admin-post.php"] [unique_id "aBLhvWhpHha-h36oCB5guQAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-10 09:14:39
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 161.123.209.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 161.123.209.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 10 05:14:35.079943 2024] [security2:error] [pid 5313:tid 5313] [client 161.123.209.124:55619] [client 161.123.209.124] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||midwayisland.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "midwayisland.com"] [uri "/wp-content/debug.log"] [unique_id "Zwea-y3rsbaSMzj4LJr15gAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-10-08 04:55:24
(1 year ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-21 23:56:44
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 161.123.209.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 161.123.209.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 21 18:56:36.884475 2023] [security2:error] [pid 18880:tid 47321397999360] [client 161.123.209.124:46259] [client 161.123.209.124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.staging.kettlehill.com"] [uri "/wp-config.php.txt"] [unique_id "ZV1DtDlyYx9jSOuFOnh1MAAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
Andrew Katz
2023-10-04 21:17:20
(2 years ago)
Common attack or app scan event detected and blocked
Port Scan
Hacking
Web App Attack
๐ณ๐ฑ
true.nl
2023-08-24 20:00:00
(3 years ago)
This IP was part of a DDoS http flood on fietsunie.nl [87.233.134.87] from UTC 24-08-2023 18:00 unt ...
show more
This IP was part of a DDoS http flood on fietsunie.nl [87.233.134.87] from UTC 24-08-2023 18:00 until 25-08-2023 1:00
show less
DDoS Attack
๐ฎ๐ช
RoboSOC
2023-04-27 20:39:39
(3 years ago)
HTTP Directory Traversal Vulnerability , PTR: PTR record not found
Hacking