๐บ๐ธ
TPI-Abuse
2026-09-27 16:29:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 12:29:47.586809 2026] [security2:error] [pid 28783:tid 28820] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:51628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slicebible.org"] [uri "/sftp-config.json"] [unique_id "arlEe2nZo2I2r2RPPekTcgAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 15:30:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 11:30:18.431427 2026] [security2:error] [pid 14750:tid 14750] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:52172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "silsby.com"] [uri "/sftp-config.json"] [unique_id "ark2ijQVOD8yUlx6f7v2TwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 15:00:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 11:00:52.318265 2026] [security2:error] [pid 1674:tid 1674] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:59539] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.markshvarts.com"] [uri "/sftp-config.json"] [unique_id "arkvpPbMy2U6Q5vTJ9S8vgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 14:27:35
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 10:27:31.457414 2026] [security2:error] [pid 15416:tid 15416] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:63756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "silalaw.com"] [uri "/sftp-config.json"] [unique_id "arkn0w9sD-iMvToglpOIHwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 13:33:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 09:33:48.381324 2026] [security2:error] [pid 30454:tid 30454] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:56739] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sketchnotebook.com"] [uri "/sftp-config.json"] [unique_id "arkbPIW4rTRQnUaddrmZmwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 12:53:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 08:53:14.725387 2026] [security2:error] [pid 8870:tid 8870] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:49184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sisix.net"] [uri "/sftp-config.json"] [unique_id "arkRuqXTOMyk5EU8IWGqUAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-27 09:50:35
(3 days ago)
[SunSep2711:50:30.8075362026][security2:error][pid3488702:tid3488835][client2a04:3543:1000:2310:18c5 ...
show more
[SunSep2711:50:30.8075362026][security2:error][pid3488702:tid3488835][client2a04:3543:1000:2310:18c5:4cff:fe3c:522f:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"sisuconsulting.net\"][uri\"/sftp-config.json\"][unique_id\"arjm5jlXw09svHEkTyCMTAAAAVM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 06:47:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 02:47:27.591597 2026] [security2:error] [pid 6030:tid 6030] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:58684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sigrc.org"] [uri "/sftp-config.json"] [unique_id "ari7_y3o-4gVagbfY6XlkQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 06:13:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 02:13:05.072142 2026] [security2:error] [pid 7585:tid 7585] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:51845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slartibartfast.com"] [uri "/sftp-config.json"] [unique_id "ariz8Z2UkqnMkHZ94-34NgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 04:44:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 00:44:01.202710 2026] [security2:error] [pid 26299:tid 26360] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:55938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skillcert.org"] [uri "/sftp-config.json"] [unique_id "arifEZk2rOnFPquEHV7jCQAAAYU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-27 04:36:50
(4 days ago)
254 requests with url.path *config.json
147 requests with url.path *ftp-sync.json
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-27 03:02:03
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 23:01:55.980310 2026] [security2:error] [pid 16197:tid 16197] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:52205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "simplyexquisitetravels.com"] [uri "/sftp-config.json"] [unique_id "ariHIwIymsB-tdly-inEKgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 00:46:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 20:46:49.895729 2026] [security2:error] [pid 20380:tid 20380] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:52500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sislau.net"] [uri "/sftp-config.json"] [unique_id "arhneUOJ4NQX2Q_kboaYAAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 00:21:58
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 20:21:54.429866 2026] [security2:error] [pid 11040:tid 11040] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:49381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slc.com.gt"] [uri "/sftp-config.json"] [unique_id "arhhokHgwNayYglJ844rZwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 00:04:06
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4 ...
show more
(mod_security) mod_security (id:949110) triggered by 2a04:3543:1000:2310:18c5:4cff:fe3c:522f (18c5-4cff-fe3c-522f.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 20:04:01.444921 2026] [security2:error] [pid 18916:tid 18916] [client 2a04:3543:1000:2310:18c5:4cff:fe3c:522f:53054] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "slapai.org"] [uri "/sftp-config.json"] [unique_id "arhdcaGJnE1sZW1iYIuGsAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack