๐บ๐ธ
TPI-Abuse
2026-06-04 11:27:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalca ...
show more
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalcapacity.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 07:27:01.444209 2026] [security2:error] [pid 16052:tid 16052] [client 64.105.88.106:58480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "21north.com"] [uri "/sftp-config.json"] [unique_id "aiFhBd5c5OEP3FVz9DA90wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 07:50:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalca ...
show more
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalcapacity.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 03:50:23.527073 2026] [security2:error] [pid 29492:tid 29492] [client 64.105.88.106:19874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arkml.com"] [uri "/sftp-config.json"] [unique_id "aiEuP0RHHMRxgTGpWA5BwQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 20:41:50
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalca ...
show more
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalcapacity.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 16:41:45.891611 2026] [security2:error] [pid 4266:tid 4266] [client 64.105.88.106:11214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rimworld.com"] [uri "/notra//sftp-config.json"] [unique_id "aiCRiepx0cjpubI-gH72swAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 20:13:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalca ...
show more
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalcapacity.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 16:12:50.168609 2026] [security2:error] [pid 9087:tid 9087] [client 64.105.88.106:40248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adampayments.com"] [uri "/sftp-config.json"] [unique_id "ah85QokBE4ABB-zEAlSVYAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
dispensight
2026-06-02 14:01:51
(1 day ago)
Automated web scanner: 1 GET request to s01-app.dispensight.ca. Paths: /. UA: Mozilla/5.0 (Windows N ...
show more
Automated web scanner: 1 GET request to s01-app.dispensight.ca. Paths: /. UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36. Datacamp Limited (Auckland, New Zealand).
show less
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-06-02 05:32:14
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 06:37:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalca ...
show more
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalcapacity.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 02:37:11.140578 2026] [security2:error] [pid 25765:tid 25765] [client 64.105.88.106:53138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aboutahome.net"] [uri "/sftp-config.json"] [unique_id "ah0ol0rV2GCjHpvNgYOAgAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 06:54:56
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalca ...
show more
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalcapacity.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 02:54:52.177870 2026] [security2:error] [pid 14795:tid 14795] [client 64.105.88.106:38332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atlwarehouse.net"] [uri "/sftp-config.json"] [unique_id "ahvbPDlWWIZOUSyMdgAVEQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-30 16:06:22
(4 days ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 23:31:20
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalca ...
show more
(mod_security) mod_security (id:210492) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalcapacity.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 19:31:11.075235 2026] [security2:error] [pid 18619:tid 18619] [client 64.105.88.106:65442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "destintoday.com"] [uri "/sftp-config.json"] [unique_id "ahohvzHRUctNDfV9Q8iw4AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-29 21:59:08
(5 days ago)
Auto-ban: >3000 req/min op 2026-05-29
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-29 12:52:34
(6 days ago)
(mod_security) mod_security (id:949110) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalca ...
show more
(mod_security) mod_security (id:949110) triggered by 64.105.88.106 (h-64-105-88-106.snva.ca.globalcapacity.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 08:52:22.278822 2026] [security2:error] [pid 25877:tid 25877] [client 64.105.88.106:8694] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "alliancegroupga.com"] [uri "/sftp-config.json"] [unique_id "ahmMBpR8oLAkWtFcKCBPVAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-27 14:51:57
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
Anonymous
2026-05-24 20:17:00
(1 week ago)
Multiple Violations by Bot
Port Scan
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-24 17:48:24
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack