๐ซ๐ท
bigorre.org
2026-08-21 15:40:35
(3 days ago)
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-07-18 14:55:50
(1 month ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-07-13 10:17:27
(1 month ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-01 03:03:22
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 23:03:17.592747 2026] [security2:error] [pid 7577:tid 7678] [client 216.74.115.50:38593] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.net"] [uri "/settings.php.bak"] [unique_id "ahz2dY6nP6TlQzUBlJvbZgAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-05-21 07:15:57
(3 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 216.74.115.50 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 216.74.115.50 (US/United States/-)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-17 10:54:39
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 05:54:30.106942 2026] [security2:error] [pid 23681:tid 23681] [client 216.74.115.50:44493] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.prod.local"] [unique_id "aWtqZjqzJ0ic2cgZHjvK6wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Kurtbaby
2025-12-30 18:12:00
(7 months ago)
Part of a coordinated attack from many different source IPs that targeted our company's VPN Christma ...
show more
Part of a coordinated attack from many different source IPs that targeted our company's VPN Christmas Eve through the end of the 26th.
show less
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-29 17:34:32
(7 months ago)
(mod_security) mod_security (id:220150) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:220150) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 12:33:50.150601 2025] [security2:error] [pid 27855:tid 28172] [client 216.74.115.50:34575] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:id. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||ftp.kettlehill.com|F|2"] [data "-1unionselect1,md5(999999999),3,4,5--"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ftp.kettlehill.com"] [uri "/admin/manage_user.php"] [unique_id "aVK7fq0TyVBQ9TgqIEW9jAAAAQY"], referer: http://ftp.kettlehill.com/admin/manage_user.php?id=-1%20union%20select%201,md5(999999999),3,4,5--+
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 09:04:32
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:04:14.155141 2025] [security2:error] [pid 12416:tid 12416] [client 216.74.115.50:53977] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/localhost.key"] [unique_id "aRWfDgK1BZJ_wOVU-N0yLgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 14:43:03
(10 months ago)
(mod_security) mod_security (id:217200) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217200) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 10:42:56.144242 2025] [security2:error] [pid 17241:tid 17253] [client 216.74.115.50:57841] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||kettlehill.kettlehill.com:443|F|2"] [data "/cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "kettlehill.kettlehill.com"] [uri "/cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh"] [unique_id "aN098Kh4GLz6vZLSqBypqQAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 00:24:30
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:24:21.989783 2025] [security2:error] [pid 172228:tid 172431] [client 216.74.115.50:42407] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /components/com_moofaq/includes/file_includer.php?gzip=0&file=/../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/components/com_moofaq/includes/file_includer.php"] [unique_id "aIVxteyxIbVHpqlXWTqLHAAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 19:50:23
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.74.115.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 15:50:13.516934 2025] [security2:error] [pid 3358226:tid 3358226] [client 216.74.115.50:37863] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.farmers123.com"] [uri "/wp-config.php.html"] [unique_id "aDi6dexKsJBr8GXm3J5rwQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-17 17:10:06
(1 year ago)
| PHPMyAdmin scans (looking for setup.php).
Hacking
SQL Injection
Web App Attack