๐บ๐ธ
TPI-Abuse
2026-01-17 07:54:59
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 02:54:46.471717 2026] [security2:error] [pid 20554:tid 20554] [client 64.137.73.38:35571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/wp-config.php.txt"] [unique_id "aWtARhLO_aVuM1yL6SHhowAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 17:32:56
(8 months ago)
(mod_security) mod_security (id:211190) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 12:30:38.733734 2025] [security2:error] [pid 27845:tid 28143] [client 64.137.73.38:58911] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp?fileName=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.net"] [uri "/tmui/login.jsp/..;/tmui/locallb/workspace/fileRead.jsp"] [unique_id "aVK6vi6vKejRiiVeVyVjvgAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 09:25:22
(9 months ago)
(mod_security) mod_security (id:211190) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 04:25:16.797193 2025] [security2:error] [pid 2843:tid 2843] [client 64.137.73.38:51677] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.nbcnewsradio.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /images/index.html?id=%24%7B%40print_r%28%40system%28%22cat+/etc/passwd%22%29%29%7D"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/images/index.html"] [unique_id "aRWj_FMK_PQ8kuuzMKyAAwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dayda.net
2025-10-13 03:22:49
(10 months ago)
query: option=com_hsconfig&controller=../../../../../../../../../../etc/passwd%00
Bad Web Bot
๐ฉ๐ช
Alejandro Docasar
2024-11-27 21:34:25
(1 year ago)
Web App Attack
๐ฉ๐ช
ps-center
2024-11-27 08:09:41
(1 year ago)
SS1: Web Attack GET /admin/log/error.log
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2024-11-27 02:49:52
(1 year ago)
SS1: Web Attack GET /assets/file:%2f%2f/etc/passwd
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-27 02:36:09
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:221260) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 26 22:35:02.893124 2024] [security2:error] [pid 12715:tid 12905] [client 64.137.73.38:58633] [client 64.137.73.38] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpcalendars.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kettlehill.com"] [uri "/test.cgi"] [unique_id "Zx2m1izF41ATo4exCwvxywAAAEo"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-04 02:56:29
(2 years ago)
(mod_security) mod_security (id:211190) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 22:56:25.697411 2024] [security2:error] [pid 11548:tid 11548] [client 64.137.73.38:46767] [client 64.137.73.38] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.stdavids-media.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /viewrq.php?format=ps&var_filename=../../../../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stdavids-media.com"] [uri "/viewrq.php"] [unique_id "ZtfMWVK6sIQyjj3sYHaNOgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-07-27 20:28:35
(2 years ago)
(mod_security) mod_security (id:211190) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 27 16:28:30.726951 2024] [security2:error] [pid 22441:tid 22501] [client 64.137.73.38:49933] [client 64.137.73.38] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||staging.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /img.php?f=/./etc/./passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.kettlehill.com"] [uri "/img.php"] [unique_id "ZqVYbttjGEvj7KjXnvD-OQAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ps-center
2024-07-15 19:16:52
(2 years ago)
SS1: Web Attack GET /wp-admin/admin-ajax.php?action=mec_load_single_page&time=1
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-07-13 23:00:19
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-05-15 01:52:36
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.137.73.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 14 21:52:32.111783 2024] [security2:error] [pid 20072:tid 47952302995200] [client 64.137.73.38:60527] [client 64.137.73.38] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kettlehill.net"] [uri "/.env.production.local"] [unique_id "ZkQVYJM3wD4Fbah2IMwxPgAAAdY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 08:02:12
(2 years ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐ฆ๐บ
MAGIC
2024-04-18 17:08:34
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot