๐บ๐ธ
TPI-Abuse
2026-08-28 22:38:48
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 216.173.75.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 216.173.75.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:38:40.972487 2026] [security2:error] [pid 9942:tid 9942] [client 216.173.75.206:55085] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nbcnewsradio.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nbcnewsradio.com"] [uri "/\\\\windows/win.ini"] [unique_id "apIN8MJSbpufiUVZ13mXqAAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 01:49:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 216.173.75.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.173.75.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 21:47:51.415107 2026] [security2:error] [pid 11735:tid 12025] [client 216.173.75.206:37323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.com"] [uri "/wp-config.php.original"] [unique_id "ahzkx-ne12di4h9XYx4-5wAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raspi4
2025-12-31 19:23:46
(8 months ago)
Fail2Ban Ban Triggered
Brute-Force
Web App Attack
๐บ๐ธ
Kurtbaby
2025-12-30 15:39:00
(8 months ago)
Part of a coordinated attack from many different source IPs that targeted our company's VPN Christma ...
show more
Part of a coordinated attack from many different source IPs that targeted our company's VPN Christmas Eve through the end of the 26th.
show less
Hacking
Anonymous
2025-12-20 22:20:05
(8 months ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 22:48:06
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 216.173.75.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 216.173.75.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 17:48:01.090520 2025] [security2:error] [pid 30860:tid 30860] [client 216.173.75.206:54709] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.farmers123.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.farmers123.com"] [uri "/\\\\windows/win.ini"] [unique_id "aS9soU9I0jqiiWQDvVudXgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 06:03:00
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 216.173.75.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 216.173.75.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:02:37.996782 2025] [security2:error] [pid 31256:tid 31284] [client 216.173.75.206:38213] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.kettlehill.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.kettlehill.com"] [uri "/mail.kettlehill.com/error.log"] [unique_id "aS0vfW28JkE_f6YcP87xYwAAABc"], referer: http://mail.kettlehill.com/mail.kettlehill.com/error.log
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-01 15:00:01
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.173.75.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.173.75.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 10:59:56.220125 2025] [security2:error] [pid 15497:tid 15516] [client 216.173.75.206:56827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aQYgbD8P3DuTvo3jZlb2SgAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2023-04-19 01:33:04
(3 years ago)
Distributed DDOS attempts for multiple sites
DDoS Attack
Bad Web Bot
๐บ๐ธ
VSM Networks
2023-04-08 16:44:42
(3 years ago)
Credential Stuffing
Brute-Force