Anonymous
2026-09-10 11:10:23
(1 day ago)
| Common web attack.
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-08-29 04:38:51
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:37:47.516362 2026] [security2:error] [pid 1736:tid 1736] [client 45.43.189.52:52359] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nbcnewsradio.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nbcnewsradio.com"] [uri "/dump.db"] [unique_id "apJiG8308Qogf9jjdSIDpAAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
EGP Abuse Dept
2026-06-02 06:32:48
(3 months ago)
Scanning for web/db/file exploits on tpc-001.mach3builders.nl
SQL Injection
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-01 03:04:51
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 23:04:47.742892 2026] [security2:error] [pid 7732:tid 7754] [client 45.43.189.52:52219] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.net"] [uri "/wp-login.php.bak"] [unique_id "ahz2zyKq_i-FrRbJEDISTwAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-01 11:23:13
(7 months ago)
(mod_security) mod_security (id:217200) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217200) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 06:22:52.478071 2026] [security2:error] [pid 16722:tid 16890] [client 45.43.189.52:53981] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||mail.kettlehill.net:80|F|2"] [data "/cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "mail.kettlehill.net"] [uri "/cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh"] [unique_id "aX83jMyMbG6v0xSDvGJTVgAAAsQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2025-12-17 13:40:11
(8 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
🇺🇸
TPI-Abuse
2025-12-03 02:34:24
(9 months ago)
(mod_security) mod_security (id:221260) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:221260) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 21:34:17.722602 2025] [security2:error] [pid 30205:tid 30205] [client 45.43.189.52:60057] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||192.64.150.229:80|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.229"] [uri "/cgi-bin/status"] [unique_id "aS-hqUcrFbPH0qIdfFhK7gAAACQ"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-01 06:23:47
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:23:39.745478 2025] [security2:error] [pid 30768:tid 30785] [client 45.43.189.52:47689] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/.htpasswd"] [unique_id "aS00a_5kVQ-rlVW6wYRwTgAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-01 15:03:07
(11 months ago)
(mod_security) mod_security (id:212620) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:03:01.402637 2025] [security2:error] [pid 12475:tid 12486] [client 45.43.189.52:33575] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||ftp.kettlehill.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /?s=</script><script>alert(document.domain)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "ftp.kettlehill.com"] [uri "/"] [unique_id "aN1CpWCKjmgjI9kURFKLfAAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-08-05 23:38:34
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 05 19:38:25.830646 2025] [security2:error] [pid 2599:tid 2599] [client 45.43.189.52:50143] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.nbcnewsradio.com"] [uri "/admin/error.log"] [unique_id "aJKV8SHLt6AYt-5RcGH-ygAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-08-01 07:49:41
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 03:49:35.755029 2025] [security2:error] [pid 3712160:tid 3712201] [client 45.43.189.52:34479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kettlehill.net"] [uri "/.git/config"] [unique_id "aIxxj9c_-1Eg368SpPiC-gAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-06-01 05:36:15
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.189.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 01:35:13.439141 2025] [security2:error] [pid 2256136:tid 2256205] [client 45.43.189.52:42673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.old" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/wp-config.old"] [unique_id "aDvmkbVUnYIqO9hNDIS8gwAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-11-18 06:24:48
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH