๐ณ๐ฑ
Roderic
2026-05-01 02:34:17
(1 month ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-12-27 06:36:30
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 45.61.124.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 45.61.124.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 27 01:35:49.972834 2024] [security2:error] [pid 23753:tid 23775] [client 45.61.124.180:32977] [client 45.61.124.180] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||kettlehill.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /horde/util/barcode.php?type=../../../../../../../../../../../etc/./passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.kettlehill.com"] [uri "/horde/util/barcode.php"] [unique_id "Z25Kxe1hrc_zKlQ4F2XUbgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Alejandro Docasar
2024-11-27 21:46:44
(1 year ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-27 00:12:55
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 45.61.124.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 45.61.124.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 26 20:09:21.591924 2024] [security2:error] [pid 16248:tid 16253] [client 45.61.124.180:40465] [client 45.61.124.180] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpcalendars.staging.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.staging.kettlehill.com"] [uri "/cgi-bin/test"] [unique_id "ZvX3saCPOG9JWfFC0TMZowAAAEM"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-04 02:35:13
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.61.124.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.124.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 22:35:06.174193 2024] [security2:error] [pid 26982:tid 26982] [client 45.61.124.180:42845] [client 45.61.124.180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stdavids-media.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "ZtfHWqup4ffcQWtGW_L0SQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2024-07-16 00:39:39
(1 year ago)
SS1: Web Attack GET /static/../../../a/../../../../etc/passwd
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-05 09:17:50
(1 year ago)
(mod_security) mod_security (id:226830) triggered by 45.61.124.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:226830) triggered by 45.61.124.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 05 05:17:29.927224 2024] [security2:error] [pid 14530:tid 47646802855680] [client 45.61.124.180:60273] [client 45.61.124.180] ModSecurity: Access denied with code 403 (phase 1). Operator GE matched 1 at ARGS_GET. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6392"] [id "226830"] [rev "2"] [msg "COMODO WAF: Open redirect vulnerability in the Redirect function in the StageShow plugin before 5.0.9 for WordPress (CVE-2015-5461)||cpcontacts.kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "cpcontacts.kettlehill.net"] [uri "/wp-content/plugins/stageshow/stageshow_redirect.php"] [unique_id "Zoe6KQY7BwB0-N9skOMU9gAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-29 01:05:47
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:00:43
(2 years ago)
Unauthorized login attempts []
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 06:59:48
(2 years ago)
Web Attack
DDoS Attack
Brute-Force
Web App Attack
Anonymous
2024-05-05 23:19:51
(2 years ago)
Common attack or app scan event detected and blocked
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-10 02:55:01
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 45.61.124.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.61.124.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 09 22:50:26.375375 2024] [security2:error] [pid 31283:tid 47092001072896] [client 45.61.124.180:34011] [client 45.61.124.180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.net"] [uri "/static../.git/config"] [unique_id "ZhX-cq6aFZrCsO2K3ClfDAAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-03-27 07:00:25
(2 years ago)
Unauthorized login attempts [ BI-16635]
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-03-27 06:51:24
(2 years ago)
WP scan
Web App Attack
Anonymous
2024-03-13 16:04:00
(2 years ago)
Common attack or app scan event detected and blocked
Port Scan
Hacking
Web App Attack