๐ต๐ฑ
Budyn
2026-08-24 19:16:00
(4 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.ovh | URI: /sftp-config.json | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
Aurealize
2026-08-24 18:51:29
(28 minutes ago)
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.vscode/ ...
show more
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.vscode/sftp.json.
show less
Web App Attack
Hacking
๐ฎ๐น
CoreTech srl
2026-08-24 18:48:59
(31 minutes ago)
cloudlinux2 fail2ban: 2026-08-24 20:44:11,775 fail2ban.actions [1464]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-24 20:44:11,775 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Ban 13.232.246.79cloudlinux2 fail2ban: 2026-08-24 20:44:11,798 fail2ban.filter [1464]: INFO [recidive] Found 13.232.246.79 - 2026-08-24 20:44:11cloudlinux2 fail2ban: 2026-08-24 20:44:10,124 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 13.232.246.79 - 2026-08-24 20:44:09cloudlinux2 fail2ban: 2026-08-24 20:44:11,347 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 13.232.246.79 - 2026-08-24 20:44:11cloudlinux2 fail2ban: 2026-08-24 20:44:11,783 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 13.232.246.79 - 2026-08-24 20:44:11cloudlinux2 fail2ban: 2026-08-24 20:44:11,501 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 13.232.246.79 - 2026-08-24 20:44:11cloudlinux2 fail2ban: 2026-08-24 20:44:11,632 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 13.232.246.79 - 2026-08-24 20:44:11cloudlinux2 fail2ban: 2026-0
show less
Brute-Force
๐ฏ๐ต
bokumin.org
2026-08-24 18:35:53
(44 minutes ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/sftp-config.json"] [id ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/sftp-config.json"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-24 18:33:45
(46 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /sftp-config.json
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
ambor
2026-08-24 18:23:06
(57 minutes ago)
L0ss Honeypot: SFTP config access attempt. Path: /sftp-config.json
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-24 17:53:41
(1 hour ago)
Try to access /.vscode/sftp.json
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 17:41:59
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 103.65.236.108 (108.236.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.236.108 (108.236.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 13:41:54.116162 2026] [security2:error] [pid 17187:tid 17187] [client 103.65.236.108:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "easy-byte.net"] [uri "/sftp-config.json"] [unique_id "aoyCYgNYaYyP7_VzYZgUWgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-24 17:40:27
(1 hour ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
๐ต๐ฑ
sefinek.net
2026-08-24 17:18:52
(2 hours ago)
Triggered Cloudflare WAF (firewallCustom) from ID.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from ID.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.vscode/sftp.json | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-08-24 17:11:51
(2 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ท๐ด
clauss
2026-08-24 16:52:03
(2 hours ago)
103.65.236.108 - - [24/Aug/2026:19:52:01 +0300] "GET /.vscode/sftp.json HTTP/2.0" 301 0 "-" "Mozilla ...
show more
103.65.236.108 - - [24/Aug/2026:19:52:01 +0300] "GET /.vscode/sftp.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
103.65.236.108 - - [24/Aug/2026:19:52:03 +0300] "GET /.vscode/sftp.json HTTP/2.0" 404 24890 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack
๐ธ๐ช
SkyDancer
2026-08-22 05:23:02
(2 days ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
Anonymous
2026-08-22 04:35:15
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฉ๐ช
FeG Deutschland
2026-08-22 01:55:13
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack