๐บ๐ธ
Charlesiv
2026-05-20 22:00:15
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: BLOCK
ASN: 135450 (PT Berkah Solusi ...
show more
Triggered Cloudflare WAF (firewallCustom) from ID.
Action taken: BLOCK
ASN: 135450 (PT Berkah Solusi Teknologi Informasi)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.vscode/sftp.json
Timestamp: 2026-05-20T21:22:58Z
Ray ID: 9fee665da92afd8c
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Bad Web Bot
๐ฉ๐ช
4server
2026-05-20 18:36:28
(2 weeks ago)
[WedMay2020:36:25.2230802026][security2:error][pid686263:tid686314][client103.65.237.216:0]ModSecuri ...
show more
[WedMay2020:36:25.2230802026][security2:error][pid686263:tid686314][client103.65.237.216:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"gmint.ch\"][uri\"/sftp-config.json\"][unique_id\"ag3_Kbk22TXdC4rvHDaOGAAAAE8\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
Baking333
2026-05-20 17:28:29
(2 weeks ago)
[redacted] 103.65.237.216 - - [20/May/2026:18:28:14 +0100] "GET /[redacted] HTTP/1.1" 302 5283 0/174 ...
show more
[redacted] 103.65.237.216 - - [20/May/2026:18:28:14 +0100] "GET /[redacted] HTTP/1.1" 302 5283 0/174057 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" [redacted] 103.65.237.216 - - [20/May/2026:18:28:27 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 5283 0/163400 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 16:15:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:15:17.232704 2026] [security2:error] [pid 2433:tid 2433] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail-pmg.com"] [uri "/sftp-config.json"] [unique_id "ag3eFdFVRgGKuTIsarBP1AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-05-20 15:55:21
(2 weeks ago)
sle-17 : Block hidden directories=>/.vscode/sftp.json(/)
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-20 13:21:19
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 09:21:12.674718 2026] [security2:error] [pid 7638:tid 7638] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixacast.com"] [uri "/sftp-config.json"] [unique_id "ag21SHri5ICXkoekfPA12wAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 12:33:10
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:33:06.387331 2026] [security2:error] [pid 32443:tid 32447] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindgardens.com"] [uri "/sftp-config.json"] [unique_id "ag2qAg7tWJETdIRaOGDUxAAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 11:17:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 07:17:18.517461 2026] [security2:error] [pid 16033:tid 16033] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uwsvita.org"] [uri "/sftp-config.json"] [unique_id "ag2YPvk2H9wm9VlrQkF30AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-05-19 13:54:14
(2 weeks ago)
$f2bV_matches
Hacking
Brute-Force
๐ฌ๐ง
pinguin
2026-05-19 13:50:42
(2 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from ID.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from ID.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /sftp-config.json
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฏ๐ต
bokumin.org
2026-05-19 13:49:11
(2 weeks ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/sftp-config.json"] [id ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/sftp-config.json"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-19 09:49:16
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 05:49:10.255741 2026] [security2:error] [pid 29656:tid 29656] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hvacs-aircon.com"] [uri "/sftp-config.json"] [unique_id "agwyFp2dFhedaKpsQtH5KAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
BSG Webmaster
2026-05-19 09:10:52
(2 weeks ago)
Hacking Attempt using path /sftp-config.json
Hacking
๐บ๐ธ
Epimetheus
2026-05-19 01:53:01
(2 weeks ago)
Unauthorized access attempts:
[GET] /.vscode/sftp.json
[GET] /sftp-config.json
UA: Mozilla/5.0 (Ma ...
show more
Unauthorized access attempts:
[GET] /.vscode/sftp.json
[GET] /sftp-config.json
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-18 14:08:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 10:08:34.798679 2026] [security2:error] [pid 3897:tid 3897] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kidswithcamerasmovie.com"] [uri "/sftp-config.json"] [unique_id "agsdYioKgAtXhJ4B5H6fBwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack