๐บ๐ธ
TPI-Abuse
2026-09-01 17:43:00
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:41:46.873816 2026] [security2:error] [pid 1326005:tid 1326249] [client 45.130.122.115:33233] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.com"] [uri "/sql.db"] [unique_id "apcOWjllk4rD8CgYj4EvTQAAAJU"], referer: http://kettlehill.com/sql.db
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 04:21:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 00:21:04.452025 2026] [security2:error] [pid 20267:tid 20284] [client 45.130.122.115:35727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/htaccess_for_page_not_found_redirects.htaccess"] [unique_id "akXnMN2jdzrSfO20vrEHcgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 02:11:49
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:11:15.757993 2026] [security2:error] [pid 7732:tid 7753] [client 45.130.122.115:44079] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.kettlehill.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.kettlehill.com"] [uri "/404.php.bak"] [unique_id "ahzqQyKq_i-FrRbJEDL8cwAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 11:47:13
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 06:47:10.628681 2026] [security2:error] [pid 483:tid 661] [client 45.130.122.115:33619] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.staging.kettlehill.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.staging.kettlehill.com"] [uri "/new/newhttp:/example.com"] [unique_id "aX89PgMxl-cQ0UzvOvSKIwAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-01-15 22:48:35
(7 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2025-12-03 20:10:16
(8 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ซ๐ท
SpaceHost-Server
2025-12-02 23:41:54
(8 months ago)
Brute-Force
Web App Attack
๐น๐ท
rtbh.com.tr
2025-12-02 20:10:14
(9 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-01 06:03:57
(9 months ago)
(mod_security) mod_security (id:210580) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210580) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:03:53.457936 2025] [security2:error] [pid 5083:tid 5093] [client 45.130.122.115:38363] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "etc/passwd" at ARGS:local-destination-id. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.kettlehill.com|F|2"] [data "Matched Data: etc/passwd found within ARGS:local-destination-id: /etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.kettlehill.com"] [uri "/wp-admin/admin-post.php"] [unique_id "aS0vyblODMhtlQGnj5c6NwAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2025-11-14 14:35:55
(9 months ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 14:47:38
(11 months ago)
(mod_security) mod_security (id:218420) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218420) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 10:47:05.882379 2025] [security2:error] [pid 12475:tid 12495] [client 45.130.122.115:35071] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||kettlehill.kettlehill.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "kettlehill.kettlehill.com"] [uri "/index.php"] [unique_id "aN0-6WCKjmgjI9kURFKDBwAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 16:49:28
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 12:49:24.694848 2025] [security2:error] [pid 3050732:tid 3050732] [client 45.130.122.115:46859] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".com.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/nbcnewsradio.com.db"] [unique_id "aDyElH8YkKA4Fkm7KXJ0EgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 07:00:54
(1 year ago)
(mod_security) mod_security (id:212620) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:212620) triggered by 45.130.122.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 03:00:26.692513 2025] [security2:error] [pid 2749697:tid 2749804] [client 45.130.122.115:35775] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.kettlehill.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /wp-content/plugins/forget-about-shortcode-buttons/assets/js/fasc-buttons/popup.php?source=1&ver=1</script><script>alert(document.domain)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.kettlehill.com"] [uri "/wp-content/plugins/forget-about-shortcode-buttons/assets/js/fasc-buttons/popup.php"] [unique_id "aDv6imzUxJS8AZi9Bz3WlAAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
SiliSoftware
2024-10-01 13:03:21
(1 year ago)
/phpBB3/viewforum.php?f=7&sid=ca2bfc0b397be1f09017f47ffd3fa260
Web App Attack
๐จ๐ญ
backslash
2024-08-02 17:30:06
(2 years ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot