๐บ๐ธ
TPI-Abuse
2026-01-17 15:08:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 216.173.80.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.173.80.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 10:08:30.062117 2026] [security2:error] [pid 26054:tid 26054] [client 216.173.80.63:41111] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.www"] [unique_id "aWul7q05zQTIy_KtlvH0vwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 17:57:15
(5 months ago)
(mod_security) mod_security (id:218420) triggered by 216.173.80.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:218420) triggered by 216.173.80.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 12:55:49.734874 2025] [security2:error] [pid 30292:tid 30592] [client 216.173.80.63:45451] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:-d allow_url_include=on -d auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||kettlehill.kettlehill.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:-d allow_url_include=on -d auto_prepend_file=php://input: -d allow_url_include=on -d auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "kettlehill.kettlehill.com"] [uri "/index.php"] [unique_id "aVLApYGwzh_8AlcRvOiNDwAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 10:31:06
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 216.173.80.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 216.173.80.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 05:30:58.964466 2025] [security2:error] [pid 30002:tid 30002] [client 216.173.80.63:39735] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/wp-login.php.bak"] [unique_id "aRWzYvSyHO53YWJb_i6pEwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2025-10-13 03:22:54
(7 months ago)
query: option=com_userstatus&controller=../../../../../../../../../../etc/passwd%00
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-27 00:28:33
(10 months ago)
(mod_security) mod_security (id:221260) triggered by 216.173.80.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 216.173.80.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:28:21.910829 2025] [security2:error] [pid 172225:tid 172401] [client 216.173.80.63:55191] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||www.kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/cgi-bin/test"] [unique_id "aIVypSMU3kwwovU6SBKTeAAAAFE"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-23 01:22:01
(10 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-29 18:48:33
(1 year ago)
(mod_security) mod_security (id:240950) triggered by 216.173.80.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240950) triggered by 216.173.80.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 14:36:14.190880 2025] [security2:error] [pid 3177239:tid 3177239] [client 216.173.80.63:57169] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||cpcalendars.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cpcalendars.farmers123.com"] [uri "/jira/secure/QueryComponentRendererValue!Default.jspa"] [unique_id "aDipHsaOlLC15kcoFveuWAAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2025-05-22 06:18:56
(1 year ago)
query: option=com_hsconfig&controller=../../../../../../../../../../etc/passwd%00
Bad Web Bot
๐ฉ๐ช
Nowest
2025-03-21 10:02:01
(1 year ago)
Bad behaviour when trying to access URL: /wp-login.php | Ignores robots.txt | User Agent: Mozilla/5. ...
show more
Bad behaviour when trying to access URL: /wp-login.php | Ignores robots.txt | User Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.88 Safari/537.36
show less
Bad Web Bot
Web App Attack
Anonymous
2025-02-27 16:30:10
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
Anonymous
2025-02-09 09:04:44
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH