๐บ๐ธ
TPI-Abuse
2026-06-01 01:57:08
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 21:55:07.636912 2026] [security2:error] [pid 6070:tid 6107] [client 69.58.12.70:35337] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.kettlehill.com|F|2"] [data ".kettlehill.com.db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.kettlehill.com"] [uri "/ftp.kettlehill.com.db"] [unique_id "ahzmezeU9m-yxUbTuKwTDwAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-16 11:26:45
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 06:26:40.226251 2026] [security2:error] [pid 2724:tid 2724] [client 69.58.12.70:42177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nbcnewsradio.com"] [uri "/_.htaccess"] [unique_id "aWogcO0KlHsCUyOzsAYpEgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-01-13 06:50:05
(5 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ฉ๐ช
Alejandro Docasar
2024-11-27 21:48:32
(1 year ago)
Web App Attack
๐ฉ๐ช
ps-center
2024-11-27 05:00:10
(1 year ago)
SS1: Web Attack GET /wp-admin/admin-ajax.php?action=heartbeat&admin_custom_language_toggle=1&admin_c ...
show more
SS1: Web Attack GET /wp-admin/admin-ajax.php?action=heartbeat&admin_custom_language_toggle=1&admin_custom_language_return_url=https://example.com
show less
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-26 23:17:09
(1 year ago)
(mod_security) mod_security (id:221260) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:221260) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 26 18:14:19.514397 2024] [security2:error] [pid 13656:tid 13926] [client 69.58.12.70:58687] [client 69.58.12.70] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||whm.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.kettlehill.com"] [uri "/debug.cgi"] [unique_id "Z0ZWSxj1UuNgSz8yPXubdwAAAQs"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-03 18:43:04
(1 year ago)
(mod_security) mod_security (id:212620) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:212620) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 03 14:42:56.982792 2024] [security2:error] [pid 21513:tid 21513] [client 69.58.12.70:50367] [client 69.58.12.70] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "3"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||mail.stdavids-media.com|F|2"] [data "Matched Data: <script found within REQUEST_URI: /oauth/idp/logout?post_logout_redirect_uri=<script>console.log(`xss`)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "mail.stdavids-media.com"] [uri "/oauth/idp/logout"] [unique_id "ZtdYsGZGkRhd-J6vpNZHOAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-01 01:55:15
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 31 21:51:45.891356 2024] [security2:error] [pid 3087873:tid 3087893] [client 69.58.12.70:38171] [client 69.58.12.70] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||autodiscover.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /document.php?modulepart=project&file=../../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kettlehill.net"] [uri "/document.php"] [unique_id "ZtPIsVZVdRO6ImKeyeuN5AAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-27 13:00:45
(1 year ago)
Unauthorized login attempts [ accesslogs]
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-06-27 06:50:00
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211190) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 27 02:47:29.227231 2024] [security2:error] [pid 2217:tid 47878024218368] [client 69.58.12.70:57593] [client 69.58.12.70] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /index.php?option=com_userstatus&controller=../../../../../../../../../../etc/passwd%00"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/index.php"] [unique_id "Zn0LAf5CorMQlYf_rxUTYwAAAJU"], referer: http://ftp.kettlehill.net/index.php?option=com_userstatus&controller=../../../../../../../../../../etc/passwd%00
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-08 08:02:12
(2 years ago)
Unauthorized login attempts []
Brute-Force
๐ช๐ธ
10dencehispahard SL
2024-05-08 07:06:54
(2 years ago)
Web Attack
DDoS Attack
Brute-Force
Web App Attack
Anonymous
2024-05-06 01:10:24
(2 years ago)
Ports: 2077,2078,2082,2083,2086,2087,2095,2096; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-03-22 23:16:15
(2 years ago)
(mod_security) mod_security (id:212620) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:212620) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 22 19:15:21.824126 2024] [security2:error] [pid 24061:tid 47049875343104] [client 69.58.12.70:37039] [client 69.58.12.70] ModSecurity: Access denied with code 403 (phase 2). Pattern match "<script\\\\b" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "65"] [id "212620"] [rev "4"] [msg "COMODO WAF: Cross-site Scripting (XSS) Attack||www.kettlehill.net|F|2"] [data "Matched Data: <script found within REQUEST_URI: /?author=1</script><script>alert(document.domain)</script>"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "www.kettlehill.net"] [uri "/"] [unique_id "Zf4RCYrLuaBZ8xqqzq1SywAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-25 21:24:47
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 69.58.12.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 25 16:24:19.987553 2024] [security2:error] [pid 11388] [client 69.58.12.70:55951] [client 69.58.12.70] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stdavids-media.com"] [uri "/.env"] [unique_id "ZbLRg5MM5WE3Hba79kY3DAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack