🇺🇸
TPI-Abuse
2026-09-01 17:45:59
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:45:05.911017 2026] [security2:error] [pid 1368312:tid 1368719] [client 94.176.86.42:40379] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.staging.kettlehill.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.staging.kettlehill.com"] [uri "/wwwroot.db"] [unique_id "apcPIdMEBzIOo_YkHES2DgAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-08-14 14:11:44
(3 weeks ago)
[14/Aug/2026:17:11:43 +0300] -- 94.176.86.42 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-co ...
show more
[14/Aug/2026:17:11:43 +0300] -- 94.176.86.42 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-content/uploads/sites/58/2018/11/39-25.pdf HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-01 20:28:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 15:28:37.930452 2026] [security2:error] [pid 3526:tid 3533] [client 94.176.86.42:35185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kettlehill.com"] [uri "/.wp-config.php.swp"] [unique_id "aaShdRD9eENAZPHfGtbc1AAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2025-12-25 19:10:00
(8 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2025-12-01 07:01:16
(9 months ago)
(mod_security) mod_security (id:210350) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 02:01:06.653488 2025] [security2:error] [pid 27471:tid 27497] [client 94.176.86.42:36411] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mail.kettlehill.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mail.kettlehill.net"] [uri "/login.php"] [unique_id "aS09MnLXOKC0tXS7y0k5dwAAAIk"], referer: https://mail.kettlehill.net/mcp
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-01 15:55:58
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 11:55:51.461451 2025] [security2:error] [pid 27531:tid 27550] [client 94.176.86.42:40135] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.staging.kettlehill.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "staging.kettlehill.com"] [uri "/MyErrors.log"] [unique_id "aQYth32WO2IkxYJ6zsIdgAAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Packets-Decreaser.NET
2025-09-13 05:43:48
(11 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
🇺🇸
TPI-Abuse
2025-09-01 01:10:23
(1 year ago)
(mod_security) mod_security (id:218420) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:218420) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 21:10:16.539963 2025] [security2:error] [pid 4167172:tid 4167203] [client 94.176.86.42:39439] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mail.kettlehill.net|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mail.kettlehill.net"] [uri "/index.php"] [unique_id "aLTyeOryNSoVQ-6inckeeAAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-24 14:02:39
(1 year ago)
Web attack
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-06-01 06:51:08
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 02:51:00.793084 2025] [security2:error] [pid 2256139:tid 2256266] [client 94.176.86.42:38051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.kettlehill.com"] [uri "/wp-config.php.bak"] [unique_id "aDv4VHvRuSdZj0PHFrRCzQAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-05-30 19:37:03
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 94.176.86.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 15:36:57.122490 2025] [security2:error] [pid 578809:tid 578809] [client 94.176.86.42:37761] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.nbcnewsradio.com|F|2"] [data ".nbcnewsradio.com.key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.nbcnewsradio.com"] [uri "/ssl/mail.nbcnewsradio.com.key"] [unique_id "aDoI2ZGQLaTkUx9b1Q5hTAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-07-21 16:57:55
(3 years ago)
Web Spam
Email Spam
Blog Spam
Bad Web Bot
Web App Attack
🇿🇦
IrisFlower
2023-04-13 23:01:47
(3 years ago)
Unauthorized connection attempt detected from IP address 94.176.86.42 to port 443 [J]
Port Scan
Hacking