๐บ๐ธ
TPI-Abuse
2026-06-01 02:56:40
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:56:33.239363 2026] [security2:error] [pid 7571:tid 7606] [client 31.58.18.90:52765] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.staging.kettlehill.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "staging.kettlehill.com"] [uri "/main.php.bak"] [unique_id "ahz04QB9GwiQ72im4TcungAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
NSCA-ISEU
2026-05-08 08:41:07
(3 weeks ago)
Mosparo Open Redirect (CVE-2023-5375). VT: Malicious: 1 - Suspicious: 1. AS205544 Leaseweb U ...
show more
Mosparo Open Redirect (CVE-2023-5375). VT: Malicious: 1 - Suspicious: 1. AS205544 Leaseweb UK Limited. Org: Private Customer
show less
Web App Attack
Port Scan
Open Proxy
๐ฎ๐น
Rosh
2026-01-19 20:49:41
(4 months ago)
[01/19/26 21:49:41] Too many requests
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-29 01:12:08
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 21:12:05.001465 2025] [security2:error] [pid 7274:tid 7274] [client 31.58.18.90:54341] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nbcnewsradio.com"] [uri "/admin/errors.log"] [unique_id "aQFp5PAh86pTTF0aNLHOSgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 14:48:15
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 10:47:33.572075 2025] [security2:error] [pid 12475:tid 12491] [client 31.58.18.90:58085] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.kettlehill.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.kettlehill.com"] [uri "/header.php.bak"] [unique_id "aN0_BWCKjmgjI9kURFKEAAAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-01 07:24:44
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 03:24:37.601748 2025] [security2:error] [pid 3705323:tid 3705352] [client 31.58.18.90:52299] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||staging.kettlehill.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "staging.kettlehill.com"] [uri "/..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\windows\\\\win.ini"] [unique_id "aIxrtVSqWoxQtnj67bcQsAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-22 15:30:02
(11 months ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 13:51:45
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 09:51:40.725007 2025] [security2:error] [pid 2862886:tid 2862886] [client 31.58.18.90:60973] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nbcnewsradio.com|F|2"] [data ".example.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nbcnewsradio.com"] [uri "/.example.com"] [unique_id "aDxa7H4D1P2udP-s-ePhBwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 06:40:21
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 02:40:16.350536 2025] [security2:error] [pid 2256139:tid 2256272] [client 31.58.18.90:46475] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.com"] [uri "/backup.sql"] [unique_id "aDv10HvRuSdZj0PHFrRAHQAAAQ4"], referer: http://ftp.kettlehill.com/backup.sql
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-28 20:11:38
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 31.58.18.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 28 16:11:29.106615 2025] [security2:error] [pid 1837844:tid 1837844] [client 31.58.18.90:38001] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.farmers123.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.farmers123.com"] [uri "/main.php.bak"] [unique_id "aDdt8ek-h9fJJfnsmGdtwQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack