๐บ๐ธ
TPI-Abuse
2026-09-01 18:24:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:24:22.242180 2026] [security2:error] [pid 405652:tid 405820] [client 94.176.173.56:39563] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.com"] [uri "/wp-config.php~"] [unique_id "apcYVhycFUI9fM4GPYwGWQAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 04:01:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 00:01:34.111465 2026] [security2:error] [pid 24091:tid 24210] [client 94.176.173.56:38145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kettlehill.net"] [uri "/wp-config.php.bak"] [unique_id "akXintCAl3_9ufpTltjPEwAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 01:49:09
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 21:45:58.933412 2026] [security2:error] [pid 12115:tid 12244] [client 94.176.173.56:34585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/htaccess_for_page_not_found_redirects.htaccess"] [unique_id "ahzkVriPChCM0Z_m_ynfvAAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 20:16:23
(6 months ago)
(mod_security) mod_security (id:220150) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:220150) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 15:16:13.840656 2026] [security2:error] [pid 32106:tid 32127] [client 94.176.173.56:35223] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:union(?:\\\\/\\\\*.{0,399}\\\\*\\\\/)?select)" at ARGS:bwg_tag_id_bwg_thumbnails_0[]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5662"] [id "220150"] [rev "5"] [msg "COMODO WAF: SQL injection vulnerability in Ginkgo CMS 5.0 (CVE-2013-5318)||ftp.kettlehill.net|F|2"] [data ")\\x22unionselect1,2,3,4,5,6,7,concat(md5(999999999),0x2c,8),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--g"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ftp.kettlehill.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "aaSejcyHAVRioPijSO93AgAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 07:11:44
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 02:11:37.342434 2025] [security2:error] [pid 27471:tid 27489] [client 94.176.173.56:46029] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.com"] [uri "/main.php.bak"] [unique_id "aS0_qXLXOKC0tXS7y0k9nAAAAIE"], referer: http://www.kettlehill.com/main.php.bak
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-11-21 22:39:49
(9 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 248
Exploited Host
Web App Attack
๐ฉ๐ช
CommanderRoot
2025-10-16 01:45:08
(10 months ago)
Bot crawler
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-10-01 15:53:01
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 11:52:55.716776 2025] [security2:error] [pid 30111:tid 30171] [client 94.176.173.56:33957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kettlehill.com"] [uri "/.htaccess"] [unique_id "aN1OVxH4YjaIRtXIcLCCfAAAAgE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-01 06:48:13
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:211190) triggered by 94.176.173.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 02:46:47.763664 2025] [security2:error] [pid 3550633:tid 3551253] [client 94.176.173.56:44963] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||www.kettlehill.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /wp-content/plugins/count-per-day/download.php?n=1&f=/etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kettlehill.com"] [uri "/wp-content/plugins/count-per-day/download.php"] [unique_id "aIxi19KwxXmY5Cscsa6DXgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2025-07-27 22:10:27
(1 year ago)
16 attempts against mh-modsecurity-ban on twig
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2025-07-25 23:00:02
(1 year ago)
16 attempts against mh-modsecurity-ban on twig
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2025-07-20 22:37:06
(1 year ago)
15 attempts against mh-modsecurity-ban on twig
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2025-07-20 21:21:43
(1 year ago)
16 attempts against mh-modsecurity-ban on twig
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2025-07-17 10:01:48
(1 year ago)
15 attempts against mh-modsecurity-ban on twig
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2025-07-17 06:31:45
(1 year ago)
16 attempts against mh-modsecurity-ban on twig
Brute-Force
Web App Attack