๐บ๐ธ
TPI-Abuse
2026-08-28 23:34:54
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:34:49.069481 2026] [security2:error] [pid 21724:tid 21724] [client 45.43.70.104:42791] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nbcnewsradio.com"] [uri "/.env.save"] [unique_id "apIbGV9OKrtWpEsEC6E6tAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 02:32:37
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:32:31.674121 2026] [security2:error] [pid 12707:tid 12717] [client 45.43.70.104:41979] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.net"] [uri "/log/errors.log"] [unique_id "ahzvP_r1zQOtbkd9viUwbgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 11:37:51
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 06:33:05.614763 2026] [security2:error] [pid 16722:tid 16862] [client 45.43.70.104:41993] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.net"] [uri "/www.key"] [unique_id "aX858cyMbG6v0xSDvGJd9gAAAsI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 08:24:19
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 03:24:14.364193 2026] [security2:error] [pid 6803:tid 6803] [client 45.43.70.104:41941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.old"] [unique_id "aWn1rpelw8mE52IhX1QFXAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-31 12:55:00
(7 months ago)
[Wed Dec 31 13:54:59.829747 2025] [:error] [pid 3947403:tid 3947403] [client 45.43.70.104:57239] Mod ...
show more
[Wed Dec 31 13:54:59.829747 2025] [:error] [pid 3947403:tid 3947403] [client 45.43.70.104:57239] ModSecurity: Warning. Matched "Operator `Within' with parameter `.ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll (418 characters omitted)' against variable `TX:EXTENSION' (Value: `.old/' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1039"] [id "920440"] [rev ""] [msg "URL file extension is restricted by policy"] [data ".old"] [severity "2"] [ver "OWASP_CRS/4.22.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/PROTOCOL-ENFORCEMENT"] [tag "capec/1000/210/272"] [uri "/.env.old"] [unique_id "176718569994.083469"] [ref "o4,4o5,3v5,8t
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 06:27:22
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:27:18.004336 2025] [security2:error] [pid 30768:tid 30785] [client 45.43.70.104:46685] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.net"] [uri "/.../.../.../.../.../.../.../.../.../windows/win.ini"] [unique_id "aS01Rv5kVQ-rlVW6wYRx1QAAAU0"], referer: http://ftp.kettlehill.net/.../.../.../.../.../.../.../.../.../windows/win.ini
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
Erpelstolz
2025-11-25 08:50:52
(9 months ago)
VM 131: 45.43.70.104 - - [25/Nov/2025:09:50:49 +0100] "GET /cgi-bin/printenv.pl HTTP/1.1" 301 729
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 15:49:39
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:49:36.116900 2025] [security2:error] [pid 30111:tid 30149] [client 45.43.70.104:51459] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kettlehill.net"] [uri "/.env.prod.local"] [unique_id "aN1NkBH4YjaIRtXIcLB_swAAAgA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-01 07:38:07
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 03:38:01.576607 2025] [security2:error] [pid 3332372:tid 3332375] [client 45.43.70.104:52393] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.kettlehill.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.kettlehill.net"] [uri "/main.php.bak"] [unique_id "aIxu2R33aKcnOojmIbhpJQAAAoE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 07:05:24
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 03:05:18.464518 2025] [security2:error] [pid 2762044:tid 2762065] [client 45.43.70.104:47763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aDv7rglM7g4oxUkvwMwJtwAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-31 22:10:02
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-30 19:44:00
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.70.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 15:43:51.116097 2025] [security2:error] [pid 583747:tid 583747] [client 45.43.70.104:51065] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nbcnewsradio.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nbcnewsradio.com"] [uri "/host.key"] [unique_id "aDoKd-NUDZFGNmu3gLTC9QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-05-23 21:50:37
(2 years ago)
"Proxies that are used for attacking
https://pastebin.com/JZr9dSDT"
Open Proxy
Anonymous
2024-05-23 21:50:37
(2 years ago)
"Proxies that are used for attacking
https://pastebin.com/JZr9dSDT"
Open Proxy
Anonymous
2024-05-23 21:50:37
(2 years ago)
"Proxies that are used for attacking
https://pastebin.com/JZr9dSDT"
Open Proxy