๐บ๐ธ
TPI-Abuse
2026-09-17 05:21:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.239.246.26 (vmi3580421.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.246.26 (vmi3580421.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:21:04.945178 2026] [security2:error] [pid 10383:tid 10383] [client 85.239.246.26:47042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killeenbarrelsandtotes.com"] [uri "/sftp-config.json"] [unique_id "aqt4wPIbhn9WfdbS0LRm5wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 05:05:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.239.246.26 (vmi3580421.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.246.26 (vmi3580421.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:05:38.583544 2026] [security2:error] [pid 16790:tid 16790] [client 85.239.246.26:38842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boxfactorylofts.com"] [uri "/sftp-config.json"] [unique_id "aqt1IrxgwzYrQiHm4HCCQQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:12:04
(21 hours ago)
(mod_security) mod_security (id:210580) triggered by 85.239.246.26 (vmi3580421.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210580) triggered by 85.239.246.26 (vmi3580421.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:12:00.426055 2026] [security2:error] [pid 12905:tid 12905] [client 85.239.246.26:46740] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "sftp-config.json" at REQUEST_COOKIES:handl_url. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||dockrockukiah.com|F|2"] [data "Matched Data: sftp-config.json found within REQUEST_COOKIES:handl_url: https:/midwestcashoffer.com/sftp-config.json"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "dockrockukiah.com"] [uri "/.vscode/sftp.json"] [unique_id "aqqjsBQLYIvENVuvLSBi4QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:44:26
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.239.246.26 (vmi3580421.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.246.26 (vmi3580421.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:44:22.815086 2026] [security2:error] [pid 6847:tid 6847] [client 85.239.246.26:33328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "afjm.org"] [uri "/sftp-config.json"] [unique_id "aqqdNptT3HVMKWWvMh7hYQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-09-16 05:16:44
(1 day ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:54
(1 day ago)
2 attacks on password/key grabbing URLs:
GET /.vscode/sftp.json HTTP/1.1
Hacking
๐ฉ๐ช
BlueWire Hosting
2026-09-16 04:08:32
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ซ๐ท
claude CALVET
2026-09-16 03:11:58
(1 day ago)
gee-17 : Block hidden directories=>/.vscode/sftp.json(/)
Hacking