|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 12:49:51.565624 2026] [security2:error] [pid 21150:tid 21150] [client 23.94.138.27:60573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/_.htaccess"] [unique_id "aWvLv2v7qoWAo5aiH28WPgAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:212620) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.co ...
show more
(mod_security) mod_security (id:212620) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:12:13.622724 2025] [security2:error] [pid 22842:tid 23017] [client 23.94.138.27:35411] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||ftp.kettlehill.net|F|2"] [data "Matched Data: <script found within REQUEST_URI: /error?msg=</script><script>alert(document.domain)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "ftp.kettlehill.net"] [uri "/error"] [unique_id "aVLSjVKoonkfA7MmLZceYwAAAQ8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210730) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 03:57:26.863876 2025] [security2:error] [pid 28383:tid 28383] [client 23.94.138.27:58807] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/application/logs/default.log"] [unique_id "aRWddjjcdpF_SkMITS7czgAAACA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
dayda.net
|
|
query: op=fileviewer&file=/etc/passwd
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 26 18:19:25.485407 2024] [security2:error] [pid 14709:tid 14871] [client 23.94.138.27:33559] [client 23.94.138.27] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.kettlehill.net"] [uri "/wp-content/plugins/wpsite-background-takeover/exports/download.php"] [unique_id "Z0ZXfaT8ZjqC-hUlXJfhYAAAAE8"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.co ...
show more
(mod_security) mod_security (id:225170) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 26 19:08:18.812312 2024] [security2:error] [pid 532018:tid 532399] [client 23.94.138.27:34157] [client 23.94.138.27] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kettlehill.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kettlehill.kettlehill.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Zs0K4i_p85EHRlaaQPgmRgAAAFY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Common attack or app scan event detected and blocked
|
Port Scan
Hacking
Web App Attack
|
|
|
๐ช๐ธ
10dencehispahard SL
|
|
Unauthorized login attempts [ accesslogs]
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210580) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210580) triggered by 23.94.138.27 (23-94-138-27-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 28 19:02:08.748665 2024] [security2:error] [pid 13009:tid 47260733523712] [client 23.94.138.27:48701] [client 23.94.138.27] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:local-destination-id. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.staging.kettlehill.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:local-destination-id: /etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "staging.kettlehill.com"] [uri "/wp-admin/admin-post.php"] [unique_id "ZlZicGl82bdmosN1lzoC2wAAAJg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ช๐ธ
10dencehispahard SL
|
|
Unauthorized login attempts []
|
Brute-Force
|
|
|
๐ช๐ธ
10dencehispahard SL
|
|
Web Attack
|
DDoS Attack
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
|
Web Spam
|
|
|
๐ฆ๐บ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐ฆ๐บ
oncord
|
|
Form spam
|
Web Spam
|
|
|
๐ช๐ธ
10dencehispahard SL
|
|
Unauthorized login attempts [ BI-16635]
|
Brute-Force
|
|