๐บ๐ธ
TPI-Abuse
2025-12-02 22:59:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 17:59:01.688126 2025] [security2:error] [pid 26472:tid 26472] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "archive.yggdrasil.org"] [uri "/sftp-config.json"] [unique_id "aS9vNdR9RUVSrlN318LAfAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
S.O.B.A. Dev.
2025-12-02 18:01:26
(6 months ago)
Threat Blocked by BeeHive from (ASN:135450) (Network:IDNIC-BSTI-AS-ID PT Berkah Solusi Teknologi Inf ...
show more
Threat Blocked by BeeHive from (ASN:135450) (Network:IDNIC-BSTI-AS-ID PT Berkah Solusi Teknologi Informasi) (Host:soba.dev) (Method:GET) (Protocol:HTTP/1.1) (Timestamp:2025-12-02T18:01:26Z)
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
octageeks.com
2025-12-01 05:06:05
(6 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐น๐ท
rtbh.com.tr
2025-11-30 20:10:12
(6 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐จ๐ฟ
ddw
2025-11-30 11:20:45
(6 months ago)
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
Web App Attack
๐ฉ๐ช
oh.mg
2025-11-30 06:17:05
(6 months ago)
[Sun Nov 30 07:17:03.554240 2025] [security2:error] [pid 2747784:tid 2747816] [client 103.65.237.216 ...
show more
[Sun Nov 30 07:17:03.554240 2025] [security2:error] [pid 2747784:tid 2747816] [client 103.65.237.216:51282] [client 103.65.237.216] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mmn.name"] [uri "/sftp-config.json"] [unique_id "aSvhXyXmeFKieReb3iqLMQAAABY"]
[Sun Nov 30 07:17:05.187492 2025] [security2:error] [pid 2747784:tid 2747805] [client 103.65.237.216:53784] [client 103.65.237.216] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-d
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2025-11-30 03:15:05
(6 months ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2025-11-30 01:02:14
(6 months ago)
Failed attempt detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ซ๐ท
SpaceHost-Server
2025-11-29 23:26:36
(6 months ago)
Brute-Force
Web App Attack
๐น๐ท
rtbh.com.tr
2025-11-29 20:10:11
(6 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ณ๐ฑ
MM-bot
2025-11-29 08:02:44
(6 months ago)
URL-probe: HTTP/1.1 GET request on /sftp-config.json (2025-11-29 09:02:44 UTC+1)
Hacking
Web App Attack
Anonymous
2025-11-29 01:24:18
(6 months ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
blizzard
2025-11-29 00:16:35
(6 months ago)
Unauthorized HTTP/1.1 GET /.vscode/sftp.json blocked by Custom rules; requester ignored robots.txt: ...
show more
Unauthorized HTTP/1.1 GET /.vscode/sftp.json blocked by Custom rules; requester ignored robots.txt: (ASN: 135450) (Network: IDNIC-BSTI-AS-ID PT Berkah Solusi Teknologi Informasi) (Method: GET) (Path: /.vscode/sftp.json) (Query: ) (User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0)
show less
Port Scan
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 23:58:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 18:58:45.524307 2025] [security2:error] [pid 8782:tid 8782] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forsaleincr.com"] [uri "/sftp-config.json"] [unique_id "aSo3NfgGstuRgKKICM4YmgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2025-11-28 23:26:32
(6 months ago)
Brute-Force
Web App Attack