๐บ๐ธ
TPI-Abuse
2026-01-17 15:24:14
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationam ...
show more
(mod_security) mod_security (id:210492) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationamerica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 10:24:08.454163 2026] [security2:error] [pid 2648:tid 2648] [client 45.127.248.243:49955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.old"] [unique_id "aWupmEN425zs8kNs-1kyGwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyuuzyou
2024-11-26 06:53:57
(1 year ago)
Intensive scraping: /web?s=%22Please%20enter%20the%20email%20address%20associated%20with%20your%20Us ...
show more
Intensive scraping: /web?s=%22Please%20enter%20the%20email%20address%20associated%20with%20your%20User%20account.%20Your%20username%20will%20be%20emailed%20to%20the%20email%20address%20on%20file.%22&scraper=ddg. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 OPR/89.0.4447.51.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-09-03 18:49:03
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationam ...
show more
(mod_security) mod_security (id:210492) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationamerica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 14:48:53.559855 2024] [security2:error] [pid 1395:tid 1395] [client 45.127.248.243:44285] [client 45.127.248.243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stdavids-media.com"] [uri "/.env.development.local"] [unique_id "ZtdaFQ_lh1N4vSn-95oVkAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-01 01:57:04
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationam ...
show more
(mod_security) mod_security (id:211190) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationamerica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 31 21:56:53.997329 2024] [security2:error] [pid 3087873:tid 3087886] [client 45.127.248.243:37957] [client 45.127.248.243] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_kif_nexus&controller=../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/index.php"] [unique_id "ZtPJ5VZVdRO6ImKeyeuSLwAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-23 05:08:04
(1 year ago)
45.127.248.243 - - [23/Aug/2024:07:08:04 +0200] "GET /Videos/1/hls/m/..%5C..%5C..%5C..%5C..%5C..%5CW ...
show more
45.127.248.243 - - [23/Aug/2024:07:08:04 +0200] "GET /Videos/1/hls/m/..%5C..%5C..%5C..%5C..%5C..%5CWindows%5Cwin.ini/stream.mp3/ HTTP/1.1" 301 5657 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" 2662
...
show less
Hacking
๐ฉ๐ช
dayda.net
2024-07-13 03:54:09
(1 year ago)
query: ../../../../../../../../../../etc/passwd
Bad Web Bot
๐ช๐ธ
10dencehispahard SL
2024-06-27 16:08:28
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-06-27 07:03:30
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationam ...
show more
(mod_security) mod_security (id:210492) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationamerica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 27 03:03:24.785900 2024] [security2:error] [pid 31354:tid 47386378376960] [client 45.127.248.243:35331] [client 45.127.248.243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.net"] [uri "/.env.bak"] [unique_id "Zn0OvG16tgjLDvCz7qLh0wAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:00:43
(2 years ago)
Unauthorized login attempts []
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:52:51
(2 years ago)
Web Attack
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-03 18:31:11
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationam ...
show more
(mod_security) mod_security (id:210730) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationamerica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 03 14:31:03.596134 2024] [security2:error] [pid 29639:tid 47764778288896] [client 45.127.248.243:47339] [client 45.127.248.243] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||staging.kettlehill.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "staging.kettlehill.com"] [uri "/staging.kettlehill.com/errors.log"] [unique_id "Zg2gZ0MbCuCCUcnq7J_FVgAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-03-27 07:00:25
(2 years ago)
Unauthorized login attempts [ BI-16635]
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-03-27 06:44:09
(2 years ago)
WP scan
Web App Attack
Anonymous
2024-02-13 10:16:56
(2 years ago)
Common attack or app scan event detected and blocked
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-26 19:53:05
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationam ...
show more
(mod_security) mod_security (id:210492) triggered by 45.127.248.243 (243.248.127.45-ns1.colocationamerica.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 26 14:52:59.061054 2024] [security2:error] [pid 9477] [client 45.127.248.243:56837] [client 45.127.248.243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.stdavids-media.com"] [uri "/api/.env"] [unique_id "ZbQNm28gi-2jquhC7eeA9gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack