๐บ๐ธ
TPI-Abuse
2026-01-17 18:19:52
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 31.57.90.130 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.57.90.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 13:19:48.895274 2026] [security2:error] [pid 15438:tid 15438] [client 31.57.90.130:58867] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/js../.git/config"] [unique_id "aWvSxBsgr9mOsRd7Z4ePMAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 18:18:08
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 31.57.90.130 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.57.90.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 13:17:39.129668 2025] [security2:error] [pid 30274:tid 30561] [client 31.57.90.130:58865] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.com"] [uri "/.svn/entries"] [unique_id "aVLFw0PUzqrf53yng5XHFQAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 02:50:00
(9 months ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐ฎ๐ช
RoboSOC
2025-10-16 08:34:35
(10 months ago)
Bash Remote Code Execution Vulnerability , PTR: PTR record not found
Hacking
๐ฉ๐ช
dayda.net
2025-10-13 03:23:35
(10 months ago)
url=http://example.com
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-27 01:14:47
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 31.57.90.130 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.57.90.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 21:14:40.420439 2025] [security2:error] [pid 404369:tid 404480] [client 31.57.90.130:51651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kettlehill.net"] [uri "/.env.dev.local"] [unique_id "aIV9gI1ApCwrT9-Kn8XCywAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-23 15:28:38
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-29 15:30:36
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 31.57.90.130 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:221260) triggered by 31.57.90.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 11:30:14.088864 2025] [security2:error] [pid 2876280:tid 2876280] [client 31.57.90.130:57407] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||autodiscover.farmers123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.farmers123.com"] [uri "/cgi-bin/test"] [unique_id "aDh9hk3f4An8ppiRelspXAAAABw"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-15 09:40:49
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack