|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 07:53:16.692653 2026] [security2:error] [pid 483:tid 653] [client 198.23.239.16:46741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kettlehill.com"] [uri "/.env.dev"] [unique_id "aX9MvAMxl-cQ0UzvOvSkKQAAAEc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing. ...
show more
(mod_security) mod_security (id:210730) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 01:21:22.058673 2026] [security2:error] [pid 15517:tid 15517] [client 198.23.239.16:47347] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nbcnewsradio.com"] [uri "/admin/logs/error.log"] [unique_id "aWnY4r-8yf4X8xvJ0PbwrgAAAB8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing. ...
show more
(mod_security) mod_security (id:210730) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 19:32:35.550399 2025] [security2:error] [pid 24397:tid 24397] [client 198.23.239.16:49611] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.farmers123.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.farmers123.com"] [uri "/host.key"] [unique_id "aS-FIy4FZ9P0uQts72zOnAAAAA4"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 18:49:38.144050 2025] [security2:error] [pid 30664:tid 30664] [client 198.23.239.16:38161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.nbcnewsradio.com"] [uri "/.env.save"] [unique_id "aQFIgrYzD_cHszROVxw0cwAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing. ...
show more
(mod_security) mod_security (id:210492) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 22 17:00:35.075599 2025] [security2:error] [pid 12071:tid 12071] [client 198.23.239.16:44527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.deandobkin.com"] [uri "/htaccess_for_page_not_found_redirects.htaccess"] [unique_id "aNG4891-Qrnu363ibcdZmQAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
| Common web attack.
|
Hacking
SQL Injection
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:211190) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing. ...
show more
(mod_security) mod_security (id:211190) triggered by 198.23.239.16 (198-23-239-16-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 12:08:08.231086 2025] [security2:error] [pid 340761:tid 340761] [client 198.23.239.16:50327] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /poc.jsp?cmd=cat+%2Fetc%2Fpasswd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/poc.jsp"] [unique_id "aDnX6EBbyCMj9NQMXmXa_wAAABY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐ฌ๐ง
mangomad
|
|
Repeated Apache mod_security rule triggers
|
Brute-Force
Web App Attack
|
|