๐บ๐ธ
raymarron.com
2026-04-18 00:10:14
(1 month ago)
/.vscode/sftp.json
/sftp-config.json
Web App Attack
๐บ๐ธ
BSG Webmaster
2026-04-14 04:35:16
(1 month ago)
Hacking Attempt using path /sftp-config.json
Hacking
๐ฉ๐ช
conseilgouz
2026-04-13 14:02:15
(1 month ago)
gie-17 : Block hidden directories=>/.vscode/sftp.json(/)
Hacking
๐ซ๐ท
Baking333
2026-04-13 08:54:20
(1 month ago)
[redacted] 103.65.237.216 - - [13/Apr/2026:09:53:57 +0100] "GET /[redacted] HTTP/1.1" 302 5287 0/382 ...
show more
[redacted] 103.65.237.216 - - [13/Apr/2026:09:53:57 +0100] "GET /[redacted] HTTP/1.1" 302 5287 0/382774 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" [redacted] 103.65.237.216 - - [13/Apr/2026:09:54:16 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 5287 0/53030 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-04-13 05:59:19
(1 month ago)
[redacted] 103.65.237.216 - - [13/Apr/2026:06:59:04 +0100] "GET /[redacted] HTTP/1.1" 302 5252 0/478 ...
show more
[redacted] 103.65.237.216 - - [13/Apr/2026:06:59:04 +0100] "GET /[redacted] HTTP/1.1" 302 5252 0/47845 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" [redacted] 103.65.237.216 - - [13/Apr/2026:06:59:18 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 5252 0/59593 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-04-12 20:36:04
(1 month ago)
[redacted] 103.65.237.216 - - [12/Apr/2026:21:35:46 +0100] "GET /[redacted] HTTP/1.1" 302 5282 0/594 ...
show more
[redacted] 103.65.237.216 - - [12/Apr/2026:21:35:46 +0100] "GET /[redacted] HTTP/1.1" 302 5282 0/59423 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0" [redacted] 103.65.237.216 - - [12/Apr/2026:21:36:02 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 5282 0/65121 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-12 09:06:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 12 05:06:40.375346 2026] [security2:error] [pid 2789351:tid 2789351] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forsaleincr.com"] [uri "/sftp-config.json"] [unique_id "adtgoK4xW4KxEawxwmdIIwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-11 21:35:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 17:35:29.940096 2026] [security2:error] [pid 3517022:tid 3517022] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gibitdigital.com"] [uri "/sftp-config.json"] [unique_id "adq-oY6d0ZlIvpTZhOWu_AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-04-11 20:51:17
(1 month ago)
[Sat Apr 11 22:51:17.086123 2026] [security2:error] [pid 255134:tid 255144] [client 103.65.237.216:0 ...
show more
[Sat Apr 11 22:51:17.086123 2026] [security2:error] [pid 255134:tid 255144] [client 103.65.237.216:0] [client 103.65.237.216] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mmn.eco"] [uri "/.vscode/sftp.json"] [unique_id "adq0RcnbOKi-Nv2lY0XmlgAAAQg"]
...
show less
Web App Attack
Bad Web Bot
๐ฌ๐ง
consul.to
2026-04-11 19:55:15
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
RH5
2026-04-11 19:44:37
(1 month ago)
Restricted URL probing (/sftp-config.json) (UTC 2026-04-11 19:44)
Web App Attack
๐บ๐ธ
RH5
2026-04-11 15:17:46
(1 month ago)
Restricted URL probing (/sftp-config.json) (UTC 2026-04-11 15:17)
Web App Attack
๐ซ๐ฎ
oh.mg
2026-04-11 14:19:37
(1 month ago)
[Sat Apr 11 16:19:13.964189 2026] [security2:error] [pid 1631928:tid 1631949] [client 103.65.237.216 ...
show more
[Sat Apr 11 16:19:13.964189 2026] [security2:error] [pid 1631928:tid 1631949] [client 103.65.237.216:0] [client 103.65.237.216] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mmn.ca"] [uri "/sftp-config.json"] [unique_id "adpYYbUOPKS9MwtjDQjaiAAAABA"]
[Sat Apr 11 16:19:36.731544 2026] [security2:error] [pid 1630267:tid 1630278] [client 103.65.237.216:0] [client 103.65.237.216] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-11 08:24:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 04:24:11.277766 2026] [security2:error] [pid 2589096:tid 2589096] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "luisguacache.com"] [uri "/sftp-config.json"] [unique_id "adoFK4JIQh5xodI4Vo030wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-11 05:25:33
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 103.65.237.216 (216.237.65.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 01:25:27.573512 2026] [security2:error] [pid 2500893:tid 2500893] [client 103.65.237.216:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/sftp-config.json"] [unique_id "adnbR8JTX-usqM2Vg0fqzgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack