🇫🇷
bigorre.org
2026-08-16 20:53:31
(3 weeks ago)
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-01-17 09:01:16
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 04:01:12.429553 2026] [security2:error] [pid 1231:tid 1231] [client 198.37.118.180:38077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/htaccess_for_page_not_found_redirects.htaccess"] [unique_id "aWtP2JuHNyV2zZvKX4U4vwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-12 04:37:49
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 23:36:31.800614 2025] [security2:error] [pid 2149:tid 2149] [client 198.37.118.180:60933] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.nbcnewsradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.nbcnewsradio.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRQOz0YuucNasFeYS0tVBwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
RoboSOC
2025-10-16 12:30:25
(10 months ago)
vBulletin Remote Code Execution Vulnerability, PTR: PTR record not found
Hacking
🇩🇪
dayda.net
2025-10-13 03:22:33
(10 months ago)
query: option=com_pro_desk&include_file=../../../../../../etc/passwd
Bad Web Bot
🇺🇸
TPI-Abuse
2025-09-22 21:56:22
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 22 17:56:08.864951 2025] [security2:error] [pid 13545:tid 13545] [client 198.37.118.180:38537] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||deandobkin.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deandobkin.com"] [uri "/..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\windows\\\\win.ini"] [unique_id "aNHF-D2kM8FQtSn9l6JOPAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-08-05 20:31:36
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 05 16:31:33.116509 2025] [security2:error] [pid 13156:tid 13156] [client 198.37.118.180:34701] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.nbcnewsradio.com"] [uri "/.git/config"] [unique_id "aJJqJRPPi-0RGIvomrfMmQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-07-27 00:15:23
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:14:16.051015 2025] [security2:error] [pid 172229:tid 172475] [client 198.37.118.180:36793] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kettlehill.com"] [uri "/sample.htaccess"] [unique_id "aIVvWOZd-uShJ73phjvaggAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-05-29 22:56:27
(1 year ago)
(mod_security) mod_security (id:240950) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240950) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 18:56:23.648506 2025] [security2:error] [pid 3704536:tid 3704536] [client 198.37.118.180:53405] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||whm.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whm.farmers123.com"] [uri "/jira/secure/QueryComponentRendererValue!Default.jspa"] [unique_id "aDjmF_ysINL6gfiePEYXVgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-05-04 08:40:40
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.37.118.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 04 04:40:32.548925 2025] [security2:error] [pid 3766151:tid 3766151] [client 198.37.118.180:50553] [client 198.37.118.180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nbcnewsradio.com"] [uri "/.wp-config.php.swp"] [unique_id "aBcoAG4MDiB7CESeX1vkdgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-03 18:03:42
(1 year ago)
botnet
DDoS Attack
Anonymous
2025-01-15 09:41:12
(1 year ago)
| XSS (Cross Site Scripting) attempt.
Hacking
SQL Injection
Web App Attack