πΊπΈ
TPI-Abuse
2026-07-28 04:46:50
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 00:46:45.595368 2026] [security2:error] [pid 3154864:tid 3154864] [client 23.95.80.215:53690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "birdlovesfish.com"] [uri "/sftp-config.json"] [unique_id "amg0NRKPczDy9KD3N8qkYQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 02:56:34
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 22:56:29.496870 2026] [security2:error] [pid 3943941:tid 3944068] [client 23.95.80.215:17942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bioscada.com"] [uri "/sftp-config.json"] [unique_id "amgaXU9030aBnDb2aqTTdwAAApU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 17:24:34
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 13:24:28.619165 2026] [security2:error] [pid 710752:tid 710752] [client 23.95.80.215:41622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biketurtlehill.com"] [uri "/sftp-config.json"] [unique_id "ameUTP2D5Qqw63wAbAn_VQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 15:50:08
(17 hours ago)
(mod_security) mod_security (id:210580) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210580) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:50:02.375460 2026] [security2:error] [pid 102448:tid 102514] [client 23.95.80.215:17418] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "sftp-config.json" at REQUEST_COOKIES:handl_url. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||bigwheel-design.com|F|2"] [data "Matched Data: sftp-config.json found within REQUEST_COOKIES:handl_url: https:/livebh.com/sftp-config.json"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "bigwheel-design.com"] [uri "/.vscode/sftp.json"] [unique_id "amd-Kt6KpcFeDvSPPlv9CQAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 14:41:36
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:41:31.298131 2026] [security2:error] [pid 135146:tid 135146] [client 23.95.80.215:62780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigpanda.expert"] [uri "/sftp-config.json"] [unique_id "amduGwVZhyhksp7r5X41awAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-07-27 07:36:43
(1 day ago)
[MonJul2709:36:38.1171892026][security2:error][pid2670473:tid2670588][client23.95.80.215:0]ModSecuri ...
show more
[MonJul2709:36:38.1171892026][security2:error][pid2670473:tid2670588][client23.95.80.215:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"bianchitecno.ch\"][uri\"/sftp-config.json\"][unique_id\"amcKhrb6aisAzXva4su9oAAAANg\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 03:54:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 23:54:02.657232 2026] [security2:error] [pid 972648:tid 972648] [client 23.95.80.215:10336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bgellis.com"] [uri "/sftp-config.json"] [unique_id "ambWWn-46HMIrdb346a9wQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-07-26 23:49:32
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
nyt
2026-07-26 20:44:52
(1 day ago)
Deploy Config Probe
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-26 17:26:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.co ...
show more
(mod_security) mod_security (id:210492) triggered by 23.95.80.215 (23-95-80-215-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 13:26:47.446337 2026] [security2:error] [pid 3920928:tid 3920928] [client 23.95.80.215:7934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bethanneblue.net"] [uri "/sftp-config.json"] [unique_id "amZDVxMagVob812oSpczDgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack