๐บ๐ธ
TPI-Abuse
2026-06-01 02:14:43
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:14:37.776312 2026] [security2:error] [pid 12707:tid 12732] [client 89.116.78.87:57403] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.kettlehill.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.kettlehill.com"] [uri "/default.php.bak"] [unique_id "ahzrDfr1zQOtbkd9viUqCQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 06:29:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 01:28:57.502764 2025] [security2:error] [pid 27471:tid 27510] [client 89.116.78.87:37271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.com"] [uri "/.env.backup"] [unique_id "aS01qXLXOKC0tXS7y0kr_wAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
Erpelstolz
2025-11-25 11:30:16
(6 months ago)
VM 131: 89.116.78.87 - - [25/Nov/2025:12:30:16 +0100] "GET /solr/solrdefault/debug/dump?param=Conten ...
show more
VM 131: 89.116.78.87 - - [25/Nov/2025:12:30:16 +0100] "GET /solr/solrdefault/debug/dump?param=ContentStreams&stream.url=file://c:/windows/win.ini HTTP/1.1" 301 865
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-29 13:09:39
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 29 09:09:33.334524 2025] [security2:error] [pid 28335:tid 28335] [client 89.116.78.87:40437] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.davispickering.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.davispickering.com"] [uri "/MyErrors.log"] [unique_id "aQISDR-j_hXZrqlO-zX4DAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-28 20:27:52
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 16:27:37.537402 2025] [security2:error] [pid 12182:tid 12182] [client 89.116.78.87:41417] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.nbcnewsradio.com"] [uri "/errors.log"] [unique_id "aQEnOcV-BKi5GbYfahKFXgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 16:21:17
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 12:21:09.938399 2025] [security2:error] [pid 30109:tid 30128] [client 89.116.78.87:48409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.staging.kettlehill.com"] [uri "/.env.old"] [unique_id "aN1U9ZmcYLK3QOnvb--A3gAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-22 20:50:53
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 22 16:50:48.129203 2025] [security2:error] [pid 24038:tid 24038] [client 89.116.78.87:50871] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.deandobkin.com"] [uri "/.env.backup"] [unique_id "aNG2qLTxV2vrdNwsNqyAbgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-01 07:47:36
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 03:47:33.728210 2025] [security2:error] [pid 3705323:tid 3705356] [client 89.116.78.87:54185] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.kettlehill.net|F|2"] [data ".kettlehill.net.key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.kettlehill.net"] [uri "/autodiscover.kettlehill.net.key"] [unique_id "aIxxFVSqWoxQtnj67bcaJwAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-03 04:10:04
(1 year ago)
| Common web attack.
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 21:25:22
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 17:25:17.218941 2025] [security2:error] [pid 3293357:tid 3293357] [client 89.116.78.87:43951] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nbcnewsradio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nbcnewsradio.com"] [uri "/error.log"] [unique_id "aDzFPYQyGYVP04Fk_roXgwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 05:35:41
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211190) triggered by 89.116.78.87 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 01:34:08.307809 2025] [security2:error] [pid 2256136:tid 2256226] [client 89.116.78.87:50947] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.kettlehill.net|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?patron_only_image=../../../../../../../../../../etc/passwd&patreon_action=serve_patron_only_image"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/"] [unique_id "aDvmULVUnYIqO9hNDIS6sAAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack