๐จ๐ญ
backslash
2026-04-19 00:12:01
(1 month ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-16 06:49:40
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 01:49:31.558629 2026] [security2:error] [pid 15396:tid 15396] [client 45.43.70.63:40453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nbcnewsradio.com"] [uri "/.env.live"] [unique_id "aWnfe4yxRwmzi3BDmiQargAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 18:52:16
(5 months ago)
(mod_security) mod_security (id:211190) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 13:49:19.510748 2025] [security2:error] [pid 22841:tid 22992] [client 45.43.70.63:60763] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /maint/modules/home/index.php?lang=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd%00english"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.kettlehill.com"] [uri "/maint/modules/home/index.php"] [unique_id "aVLNL7vqJPp5jxktaSF20wAAAMA"], referer: www.kettlehill.kettlehill.com/maint/index.php?packages
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 23:11:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 18:11:06.894209 2025] [security2:error] [pid 30968:tid 30968] [client 45.43.70.63:42507] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.farmers123.com"] [uri "/api/.env"] [unique_id "aS9yCtRI1dddcnZAGXoQfAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-29 10:34:17
(6 months ago)
(mod_security) mod_security (id:211190) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 05:34:05.125627 2025] [security2:error] [pid 18453:tid 18555] [client 45.43.70.63:54249] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||kettlehill.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /plugins/servlet/snjFooterNavigationConfig?fileName=../../../../etc/passwd&fileMime=$textMime"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.kettlehill.com"] [uri "/plugins/servlet/snjFooterNavigationConfig"] [unique_id "aSrMHXV7QLXY6ZC8vzZZRAAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 04:48:35
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 23:48:17.886818 2025] [security2:error] [pid 26856:tid 26856] [client 45.43.70.63:33145] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nbcnewsradio.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nbcnewsradio.com"] [uri "/header.php.bak"] [unique_id "aRQRkYwI669FBDbUtO2jjwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 00:56:47
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:56:35.569208 2025] [security2:error] [pid 404372:tid 404540] [client 45.43.70.63:43191] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.com"] [uri "/\\\\example.com"] [unique_id "aIV5QxTdKN3sxMPXSjT7XwAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 17:26:06
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 13:25:52.251536 2025] [security2:error] [pid 3070217:tid 3070217] [client 45.43.70.63:45583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.farmers123.com"] [uri "/.env.dev.local"] [unique_id "aDiYoEdvstcOytFfjQbhiAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
EGP Abuse Dept
2025-05-16 23:40:06
(1 year ago)
SQL injection attack
SQL Injection
Anonymous
2025-03-25 08:25:06
(1 year ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
Anonymous
2025-02-27 17:20:15
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-27 15:00:43
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.43.70.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 09:59:19.769775 2025] [security2:error] [pid 27063:tid 27231] [client 45.43.70.63:33041] [client 45.43.70.63] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/wp-config.php~"] [unique_id "Z8B9x8nGgNPGej7DPucTgAAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2024-10-07 09:06:51
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
nowyouknow
2024-08-29 13:01:02
(1 year ago)
(From [email protected] ) Hi, it's Jason reaching out. I just visited your website and spotte ...
show more
(From [email protected] ) Hi, it's Jason reaching out. I just visited your website and spotted a couple of areas where a few adjustments could boost your a lot more leads. I've assisted many clients in your industry enhance their sites, and they experienced substantial growth in leads because of it.
I'm happy to jump on a quick call to talk about these changes with you. I have some time this week, so free of charge just to help you out lol.
Tell me the best way to get in touch, and we can find a suitable time. It's basic stuff and shouldn't take too long to fix.
Best Regards,
Jason Clemens
** Visit: https://bit.ly/FreeWebsiteAuditByJason
Or reply to this email [email protected] or call me at: +1-651-419-8101
show less
Phishing
Web Spam
๐บ๐ธ
nowyouknow
2024-08-27 10:17:14
(1 year ago)
(From [email protected] ) Hi, this is Jason. I recently came across your website and noticed ...
show more
(From [email protected] ) Hi, this is Jason. I recently came across your website and noticed some areas where minor tweaks could help you generate a lot more leads. I've worked with numerous clients in your industry upgrade their websites, and they experienced substantial growth in leads due to these changes.
I'm happy to jump on a quick call to talk about these changes with you. I'm available this week, so free of charge just to help you out lol.
Let me know the best way to connect, and we can schedule a time that works for you. It's simple stuff and won't require much time.
Best Regards,
Jason Clemens
** Visit: https://bit.ly/FreeWebsiteAuditByJason
Or reply to this email [email protected] or call me at: +1-651-419-8101
show less
Phishing
Web Spam