๐บ๐ธ
TPI-Abuse
2026-09-01 17:00:57
(20 hours ago)
(mod_security) mod_security (id:211190) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:00:54.125932 2026] [security2:error] [pid 1170998:tid 1171007] [client 31.59.21.210:43125] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /login.php?p=..%2F..%2F..%2Fetc%2Fpasswd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.net"] [uri "/login.php"] [unique_id "apcExqFsi3ZvTVL1ve6NhgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 02:25:10
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:25:07.204135 2026] [security2:error] [pid 12707:tid 12712] [client 31.59.21.210:48649] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.kettlehill.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.kettlehill.com"] [uri "/php_errors.log"] [unique_id "ahztg_r1zQOtbkd9viUtvwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 20:55:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 16:55:40.252125 2026] [security2:error] [pid 108291:tid 108291] [client 31.59.21.210:51421] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.nbcnewsradio.com"] [uri "/.env.prod.local"] [unique_id "adbAzBkNJKrbxR17Ut6kIwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 08:22:37
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 03:22:35.071359 2026] [security2:error] [pid 3637:tid 3637] [client 31.59.21.210:49675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.production"] [unique_id "aWn1S2ZF-9LOjy7zpOL6jAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 23:44:05
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 18:43:58.538635 2025] [security2:error] [pid 7389:tid 7389] [client 31.59.21.210:60533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.farmers123.com"] [uri "/.env.save"] [unique_id "aS95vkm7L_6wbnZSRJn0CgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-29 01:59:50
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 21:59:43.106035 2025] [security2:error] [pid 21513:tid 21513] [client 31.59.21.210:34555] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nbcnewsradio.com"] [uri "/.env.backup"] [unique_id "aQF1D4NZ1bTKLfpG9BTquwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
mgarofano80
2025-10-22 15:01:52
(10 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 15:04:17
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:04:08.332606 2025] [security2:error] [pid 9487:tid 9531] [client 31.59.21.210:50747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aN1C6EvyOqnYEaX7Ie4cegAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-22 20:02:55
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 22 16:02:47.065980 2025] [security2:error] [pid 1419:tid 1419] [client 31.59.21.210:49241] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.deandobkin.com"] [uri "/.env.live"] [unique_id "aNGrZ6AeQJul3zd0CVqHlAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
KuhA
2025-09-22 01:47:00
(11 months ago)
"GET /db.php.bak HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-05 18:18:35
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.59.21.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 05 14:18:27.002287 2025] [security2:error] [pid 13692:tid 13692] [client 31.59.21.210:49193] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nbcnewsradio.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nbcnewsradio.com"] [uri "/settings.php.bak"] [unique_id "aJJK8iCyuyv4TzdVjWHW4gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-06 12:10:07
(1 year ago)
| SQL injection attempt.
Hacking
SQL Injection
Web App Attack