|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 02:18:52.355757 2026] [security2:error] [pid 6889:tid 6889] [client 31.58.18.219:43381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.bak"] [unique_id "aWs33HCuhCIE5pF52MwOWQAAACw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:211820) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211820) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 15:45:20.179120 2025] [security2:error] [pid 22839:tid 22971] [client 31.58.18.219:54645] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:; ?(?:(?:(?:trunc|cre|upd)at|renam)e|(?:inser|selec)t|de(?:lete|sc)|alter|load) ?[\\\\[(]?\\\\b\\\\w{2,}|\\\\bcreate function .+ returns\\\\b))" at ARGS:rfilter. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "63"] [id "211820"] [rev "4"] [msg "COMODO WAF: Detects MySQL UDF injection and other data/structure manipulation attempts||ftp.kettlehill.net|F|2"] [data "Matched Data: ;SELECT SLEEP found within ARGS:rfilter: \\x22or \\x22\\x22=\\x22((\\x22));SELECT SLEEP(10);"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "ftp.kettlehill.net"] [uri "/graph_view.php"] [unique_id "aVLoYKhQT-NrkrxX7z3xewAAAEs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:221260) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:221260) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 19:04:41.751843 2025] [security2:error] [pid 26448:tid 26516] [client 31.58.18.219:57963] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||www.staging.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.staging.kettlehill.com"] [uri "/cgi-bin/status/status.cgi"] [unique_id "aSjnGTQHpSRlBomdSGyvSgAAAJY"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:211190) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:47:51.082115 2025] [security2:error] [pid 14325:tid 14325] [client 31.58.18.219:34525] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /maint/modules/home/index.php?lang=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd%00english"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/maint/modules/home/index.php"] [unique_id "aRWpRyigEC_UsqtPq7Y2cQAAAAc"], referer: ftp.nbcnewsradio.com/maint/index.php?packages
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:212620) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 29 15:18:24.617078 2025] [security2:error] [pid 12939:tid 12939] [client 31.58.18.219:37621] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at ARGS_NAMES:bhl4n%22%3e%3cScRiPt%3ealert%28'document_domain'%29%3c%2fScRiPt%3eiyehb. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.davispickering.com|F|2"] [data "Matched Data: <script found within ARGS_NAMES:bhl4n%22%3e%3cScRiPt%3ealert%28'document_domain'%29%3c%2fScRiPt%3eiyehb: bhl4n\\x22><script>alert('document_domain')</script>iyehb"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.davispickering.com"] [uri "/furniture/catalog/all-products"] [unique_id "aQJogLKWRCh7-usAhSIgYAAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240950) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240950) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:52:32.194625 2025] [security2:error] [pid 404370:tid 404575] [client 31.58.18.219:36113] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||www.staging.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.staging.kettlehill.com"] [uri "/_users/org.couchdb.user:poc"] [unique_id "aIV4UMy-cZtwxEkIWL8ypAAAANY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
|
Brute-Force
SSH
|
|
|
π©πͺ
SCHAPPY
|
|
IP was involved in L7 DDoS attack.
|
DDoS Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 12:19:40.325745 2025] [security2:error] [pid 2957866:tid 2957866] [client 31.58.18.219:40803] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.farmers123.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.farmers123.com"] [uri "/error.log"] [unique_id "aDiJHK3tbmDlGyq4qTaZgQAAABI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.58.18.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 09:34:44.110698 2025] [security2:error] [pid 27303:tid 27405] [client 31.58.18.219:43539] [client 31.58.18.219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.staging.kettlehill.com"] [uri "/.env.stage"] [unique_id "Z8B4BFqvcS75O-zsMlKTvAAAAVY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
| Shellshock attack detected
|
Hacking
SQL Injection
Web App Attack
|
|