Anonymous
2026-10-03 08:02:45
(11 hours ago)
Web attack
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 14:02:57
(2 days ago)
Web attack
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 06:04:00
(4 days ago)
Web attack
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 04:03:11
(5 days ago)
Web attack
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 17:43:16
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:41:44.271126 2026] [security2:error] [pid 1325999:tid 1326200] [client 188.241.146.31:43755] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.com"] [uri "/ROOT.db"] [unique_id "apcOWMyS-zs3KR46Nfb3tAAAAEU"], referer: http://kettlehill.com/ROOT.db
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 04:02:31
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 00:02:23.720479 2026] [security2:error] [pid 24246:tid 24299] [client 188.241.146.31:36075] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.com"] [uri "/login.php.bak"] [unique_id "akXiz8FY8dDCSbGt3hEPrAAAAoY"], referer: http://www.kettlehill.com/login.php.bak
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 07:15:54
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 02:15:51.749332 2025] [security2:error] [pid 27471:tid 27505] [client 188.241.146.31:44219] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.com"] [uri "/404.php.bak"] [unique_id "aS1Ap3LXOKC0tXS7y0k-egAAAJE"], referer: http://www.kettlehill.com/404.php.bak
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-01 14:53:31
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 10:53:25.711953 2025] [security2:error] [pid 8590:tid 8622] [client 188.241.146.31:44199] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.kettlehill.com"] [uri "/sftp-config.json"] [unique_id "aQYe5Xl6EaMmM6sQysSbjQAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-09-02 00:17:05
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-01 04:30:31
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 00:30:25.357458 2025] [security2:error] [pid 4167007:tid 4167018] [client 188.241.146.31:33595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kettlehill.net"] [uri "/htaccess_for_page_not_found_redirects.htaccess"] [unique_id "aLUhYbJvJhw2WatQMF5VMQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bigorre.org
2025-07-08 16:38:33
(1 year ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐ฆ๐บ
MAGIC
2025-06-13 22:04:54
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-06-06 14:20:04
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 06:45:47
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 02:45:42.344208 2025] [security2:error] [pid 2636838:tid 2636930] [client 188.241.146.31:41465] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||staging.kettlehill.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "staging.kettlehill.com"] [uri "/php_errors.log"] [unique_id "aDv3Fjvwu3ccjH5oiKEUvAAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-30 16:17:32
(1 year ago)
(mod_security) mod_security (id:212760) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:212760) triggered by 188.241.146.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 12:17:22.049919 2025] [security2:error] [pid 352978:tid 352978] [client 188.241.146.31:45647] ModSecurity: Access denied with code 403 (phase 2). Pattern match "[\\\\x22'\\\\/`]on[a-z]{1,}?\\\\/{0,}=" at REQUEST_HEADERS:Referer. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "159"] [id "212760"] [rev "2"] [msg "COMODO WAF: IE XSS Filters - Attack Detected.||indie100.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "indie100.com"] [uri "/403.shtml"] [unique_id "aDnaElSd7IxX06VYPfS4mwAAABo"], referer: https://nbcnewsradio.com/control/stream?contentId=%27\\%22%3E%3Csvg/onload=alert(/xss/)%3E
show less
Brute-Force
Bad Web Bot
Web App Attack