๐บ๐ธ
TPI-Abuse
2026-10-01 02:40:57
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 22:34:27.699402 2026] [security2:error] [pid 7503:tid 7519] [client 5.183.243.16:44409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.com"] [uri "/.svn/wc.db"] [unique_id "ar3Gs8AItDKx83kbLgnu6QAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 17:58:14
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:57:44.282447 2026] [security2:error] [pid 6472:tid 6831] [client 5.183.243.16:33431] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.kettlehill.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.kettlehill.net"] [uri "/Release.db"] [unique_id "apcSGIVqO8j-a5zJhlbjNAAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 21:59:45
(2 months ago)
(mod_security) mod_security (id:212620) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212620) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 17:59:37.581550 2026] [security2:error] [pid 3417437:tid 3417588] [client 5.183.243.16:42899] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||mail.kettlehill.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /wpdmpro/list-packages/?orderby=title\\x22><script>alert(1)</script>&order=asc"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "mail.kettlehill.com"] [uri "/wpdmpro/list-packages/"] [unique_id "am5sSWLJZIC9TJ8pvwWXEQAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-06-17 08:36:12
(3 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -38.121 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -38.121 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:151.0) Gecko/20100101 Firefox/151.0
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-01 02:06:50
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:06:45.050297 2026] [security2:error] [pid 7577:tid 7682] [client 5.183.243.16:35691] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.net"] [uri "/main.php.bak"] [unique_id "ahzpNY6nP6TlQzUBlJvQAAAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 05:55:47
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 00:54:41.653502 2025] [security2:error] [pid 26090:tid 26465] [client 5.183.243.16:38997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kettlehill.net"] [uri "/api/.env"] [unique_id "aS0toQqR0geke5MRGl4KrAAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 16:39:34
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 12:39:30.634904 2025] [security2:error] [pid 30110:tid 30165] [client 5.183.243.16:36831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kettlehill.net"] [uri "/.htpasswd"] [unique_id "aN1ZQskWrLLgoGKIU589RQAAAdQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
ISPLtd
2025-09-25 21:15:59
(1 year ago)
Web server scanner, TCP/80 TCP/443, requests no pages or simple HEAD / or GET / to test server.
Bad Web Bot
๐ณ๐ฑ
exxos
2025-08-19 19:03:01
(1 year ago)
Attacks with Bad user agents
Hacking
๐บ๐ธ
TPI-Abuse
2025-08-01 07:01:34
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 03:01:28.698481 2025] [security2:error] [pid 3705323:tid 3705359] [client 5.183.243.16:44805] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.net"] [uri "/admin/log/error.log"] [unique_id "aIxmSFSqWoxQtnj67bcBgAAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-03 03:30:03
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-30 18:34:40
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 5.183.243.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 14:34:33.253725 2025] [security2:error] [pid 506039:tid 506039] [client 5.183.243.16:39743] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nbcnewsradio.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nbcnewsradio.com"] [uri "/header.php.bak"] [unique_id "aDn6Oci53t16lsHiiLyoywAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack