๐ฉ๐ช
maxpower
2026-10-03 19:07:14
(1 day ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 64.137.89.37 (ES/Spain/-): 1 in the last 3600 ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 64.137.89.37 (ES/Spain/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 64.137.89.37 - - [03/Oct/2026:21:07:07 +0200] "GET /wp-json/wp/v2/users/ HTTP/1.1" 200 12111 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.0.0 Safari/537.36" "-" host=www.keyprint.com.br
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-02-01 12:17:08
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 07:17:04.009977 2026] [security2:error] [pid 16720:tid 16856] [client 64.137.89.37:45133] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.net"] [uri "/MyErrors.log"] [unique_id "aX9EQHgN2ebRaezbXtJPkgAAAVc"], referer: http://ftp.kettlehill.net/MyErrors.log
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 06:15:19
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:15:14.544984 2025] [security2:error] [pid 31256:tid 31278] [client 64.137.89.37:56805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.com"] [uri "/.env.www"] [unique_id "aS0ycm28JkE_f6YcP876MQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 05:17:57
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 00:17:52.228376 2025] [security2:error] [pid 27101:tid 27101] [client 64.137.89.37:49029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nbcnewsradio.com"] [uri "/.htaccess"] [unique_id "aRQYgCah381vBlo82BhE3gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 15:21:28
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:21:20.563144 2025] [security2:error] [pid 31612:tid 31738] [client 64.137.89.37:35741] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.com"] [uri "/\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\..\\\\windows\\\\win.ini"] [unique_id "aN1G8PVYIT9TWn2lWzKCNAAAAQs"], referer: http://www.kettlehill.com/%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5C..%5Cwindows%5Cwin.ini
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-01 08:06:09
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 04:06:03.114214 2025] [security2:error] [pid 3705323:tid 3705360] [client 64.137.89.37:60035] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.net|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.net"] [uri "/db.php.bak"] [unique_id "aIx1a1SqWoxQtnj67bcmZwAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2025-07-27 00:08:27
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-06-06 12:00:02
(1 year ago)
| XSS (Cross Site Scripting) attempt.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 14:47:12
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 10:47:07.446324 2025] [security2:error] [pid 2930226:tid 2930226] [client 64.137.89.37:34353] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.nbcnewsradio.com|F|2"] [data ".nbcnewsradio.com.key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.nbcnewsradio.com"] [uri "/ssl/autodiscover.nbcnewsradio.com.key"] [unique_id "aDxn67ZoPC77luh02-VlxQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 05:38:15
(1 year ago)
(mod_security) mod_security (id:212750) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:212750) triggered by 64.137.89.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 01:38:11.893137 2025] [security2:error] [pid 2256136:tid 2256222] [client 64.137.89.37:51311] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\bon(?:abort|blur|change|click|dblclick|dragdrop|error|focus|keydown|keypress|keyup|load|mouse(?:down|move|out|over|up)|move|readystatechange|reset|resize|select|submit|unload)\\\\b[^a-zA-Z0-9_]{0,}?=" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "69"] [id "212750"] [rev "3"] [msg "COMODO WAF: XSS Attack Detected||kettlehill.com|F|2"] [data "Matched Data: onerror= found within REQUEST_URI: /?spai_vjs=</script><img src=1 onerror=alert(document.domain)>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "kettlehill.com"] [uri "/"] [unique_id "aDvnQ7VUnYIqO9hNDIS_QwAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack