๐บ๐ธ
TPI-Abuse
2026-01-17 08:37:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com) ...
show more
(mod_security) mod_security (id:210492) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 03:36:54.125641 2026] [security2:error] [pid 649:tid 649] [client 23.94.138.3:47451] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.dev.local"] [unique_id "aWtKJr_kqk2ZKj2xsh611QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-01-16 04:30:37
(4 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 19:36:10
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:36:03.133783 2025] [security2:error] [pid 29977:tid 29988] [client 23.94.138.3:36605] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.net"] [uri "/.../.../.../.../.../.../.../.../.../windows/win.ini"] [unique_id "aVLYIzWelXmsIDHwJWbdNAAAAYk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
RoboSOC
2025-10-16 08:38:46
(7 months ago)
phpunit Remote Code Execution Vulnerability, PTR: 23-94-138-3-host.colocrossing.com.
Hacking
๐บ๐ธ
TPI-Abuse
2025-07-27 01:17:37
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com) ...
show more
(mod_security) mod_security (id:210730) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:17:29.970113 2025] [security2:error] [pid 404369:tid 404490] [client 23.94.138.3:48401] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.net"] [uri "/db_config.php.bak"] [unique_id "aIV-KY1ApCwrT9-Kn8XIBgAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Alejandro Docasar
2024-11-27 21:56:21
(1 year ago)
Web App Attack
๐ฉ๐ช
ps-center
2024-11-27 10:40:27
(1 year ago)
SS1: Web Attack GET /wp-content/plugins/embed-swagger/swagger-iframe.php?url=aaa://%22-alert(documen ...
show more
SS1: Web Attack GET /wp-content/plugins/embed-swagger/swagger-iframe.php?url=aaa://%22-alert(document.domain)-%22
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-27 09:26:16
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com) ...
show more
(mod_security) mod_security (id:211190) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 27 05:26:10.624475 2024] [security2:error] [pid 14171:tid 14184] [client 23.94.138.3:53739] [client 23.94.138.3] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /fuel/pages/select/?filter=%27%2bpi(print(%24a%3d%27system%27))%2b%24a(%27cat%20/etc/passwd%27)%2b%27"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.net"] [uri "/fuel/pages/select/"] [unique_id "Zx4HMoo06Q7YlfH3QrOr8gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-04 03:11:40
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com) ...
show more
(mod_security) mod_security (id:211190) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 23:11:34.405606 2024] [security2:error] [pid 9081:tid 9081] [client 23.94.138.3:43823] [client 23.94.138.3] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.stdavids-media.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?action=..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stdavids-media.com"] [uri "/"] [unique_id "ZtfP5ouOgAnKOuCzyY7BQwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-01 00:53:20
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com) ...
show more
(mod_security) mod_security (id:211190) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 31 20:53:13.227462 2024] [security2:error] [pid 27294:tid 27321] [client 23.94.138.3:54595] [client 23.94.138.3] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||staging.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /catalog.php?filename=../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/catalog.php"] [unique_id "Zqrcef8VayTTxsa0mTWZuwAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-27 13:00:45
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-05-21 23:20:58
(2 years ago)
(mod_security) mod_security (id:212620) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com) ...
show more
(mod_security) mod_security (id:212620) triggered by 23.94.138.3 (23-94-138-3-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 21 19:19:32.849242 2024] [security2:error] [pid 4011:tid 47525643441920] [client 23.94.138.3:33459] [client 23.94.138.3] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_COOKIES:svpnlang. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||kettlehill.kettlehill.com|F|2"] [data "Matched Data: <script found within REQUEST_COOKIES:svpnlang: <script>alert('document.domain')</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "kettlehill.kettlehill.com"] [uri "/wnm/login/login.json"] [unique_id "Zk0sBDHjro3uQnb1ONk_swAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-05-08 17:19:00
(2 years ago)
Brute force seen in log review
Brute-Force
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:00:43
(2 years ago)
Unauthorized login attempts []
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:46:37
(2 years ago)
Web Attack
DDoS Attack
Brute-Force
Web App Attack