๐ฆ๐บ
paulshipley.com.au
2026-06-24 09:10:10
(1 hour ago)
[Wed Jun 24 19:10:09.775178 2026] [security2:error] [pid 340689] [client 158.115.255.21:15478] [clie ...
show more
[Wed Jun 24 19:10:09.775178 2026] [security2:error] [pid 340689] [client 158.115.255.21:15478] [client 158.115.255.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dlcarterauthor.com"] [uri "/sftp-config.json"] [unique_id "ajue8V3fYrBHe3kjk-ifdwAAAAw"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 08:15:11
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 04:15:05.371638 2026] [security2:error] [pid 10704:tid 10704] [client 158.115.255.21:6890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dkdesign.click"] [uri "/sftp-config.json"] [unique_id "ajuSCZz2cEdJ72Ot3yeRMQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 04:28:29
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 00:28:25.971461 2026] [security2:error] [pid 15585:tid 15585] [client 158.115.255.21:24874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "divingmachines.com"] [uri "/sftp-config.json"] [unique_id "ajtc6SU3J_4pofAmtHFlqAAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 23:07:47
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 19:07:42.603771 2026] [security2:error] [pid 26191:tid 26191] [client 158.115.255.21:45638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "discountweddingnapkins.com"] [uri "/sftp-config.json"] [unique_id "ajsRvq3FgnbVvs-RDv-t_wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 20:01:48
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 16:01:44.324073 2026] [security2:error] [pid 28144:tid 28144] [client 158.115.255.21:9392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dipseanet.com"] [uri "/sftp-config.json"] [unique_id "ajrmKN0N1tARuQeohvjTywAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 17:22:34
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 13:22:30.143678 2026] [security2:error] [pid 31567:tid 31567] [client 158.115.255.21:37128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dimitri.daras.name"] [uri "/sftp-config.json"] [unique_id "ajrA1msEJw19YCLmtHy6ZQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-06-23 14:44:03
(19 hours ago)
[redacted] 158.115.255.21 - - [23/Jun/2026:15:44:01 +0100] "GET /[redacted] HTTP/1.1" 302 6878 0/712 ...
show more
[redacted] 158.115.255.21 - - [23/Jun/2026:15:44:01 +0100] "GET /[redacted] HTTP/1.1" 302 6878 0/71234 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" [redacted] 158.115.255.21 - - [23/Jun/2026:15:44:01 +0100] "GET /[redacted] HTTP/1.1" 302 6793 0/89693 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 12:44:54
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.115.255.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 08:44:50.595180 2026] [security2:error] [pid 19331:tid 19331] [client 158.115.255.21:23664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chriseaton.com"] [uri "/sftp-config.json"] [unique_id "ajp_wqv3yfq1fwecqF0fcQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
digital-plus-experience.com
2026-06-23 11:48:50
(22 hours ago)
Probe for vulnerabilities. Path attempted: /sftp-config
Web App Attack