๐บ๐ธ
TPI-Abuse
2026-01-17 16:05:59
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 216.173.104.135 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 216.173.104.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 11:05:55.565258 2026] [security2:error] [pid 21555:tid 21555] [client 216.173.104.135:36403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.production"] [unique_id "aWuzY7u1aSmAphARhuLFkgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 12:31:12
(9 months ago)
(mod_security) mod_security (id:211190) triggered by 216.173.104.135 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:211190) triggered by 216.173.104.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 07:31:08.316608 2025] [security2:error] [pid 27990:tid 27990] [client 216.173.104.135:53329] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?action=dzsap_download&link=../../../../../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/"] [unique_id "aRXPjLV5y_lziaad5360hAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2025-10-13 03:23:04
(10 months ago)
query: option=com_jashowcase&view=jashowcase&controller=../../../../../../../etc/passwd%00
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-27 00:35:50
(1 year ago)
(mod_security) mod_security (id:212750) triggered by 216.173.104.135 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:212750) triggered by 216.173.104.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:35:46.170907 2025] [security2:error] [pid 172225:tid 172389] [client 216.173.104.135:52005] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||www.kettlehill.net|F|2"] [data "Matched Data: onerror= found within REQUEST_URI: /keepalive.php?caller=\\x22><img src=1 onerror=alert(document.domain) />&uq_mt=1664137650.085"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.kettlehill.net"] [uri "/keepalive.php"] [unique_id "aIV0YiMU3kwwovU6SBKg1QAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-07-23 01:09:12
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ช๐ธ
10dencehispahard SL
2025-06-16 05:19:18
(1 year ago)
WP probing for vulnerabilities
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-05-29 22:31:14
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 216.173.104.135 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 216.173.104.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 18:31:06.623733 2025] [security2:error] [pid 3654601:tid 3654601] [client 216.173.104.135:56055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.farmers123.com"] [uri "/.env.prod.local"] [unique_id "aDjgKu5kCX6KkC-Z3ondqAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-15 07:10:27
(1 year ago)
| XSS (Cross Site Scripting) attempt.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
ChamberofCommerce.com
2023-11-06 02:52:42
(2 years ago)
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested ...
show more
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested Before Block:226
show less
Bad Web Bot
๐บ๐ธ
ChamberofCommerce.com
2023-10-31 01:20:16
(2 years ago)
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested ...
show more
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested Before Block:226
show less
Bad Web Bot