πΊπΈ
TPI-Abuse
2026-06-11 13:51:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.156.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.156.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 09:51:11.074080 2026] [security2:error] [pid 4475:tid 4479] [client 104.28.156.216:40431] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "triestemagica.org"] [uri "/sftp-config.json"] [unique_id "aiq9TxXizEVXVo4h4T2DKwAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
nyt
2026-06-11 13:41:31
(1 day ago)
Deploy Config Probe
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-11 12:41:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.156.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.156.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 08:41:11.724807 2026] [security2:error] [pid 6842:tid 6842] [client 104.28.156.216:42073] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wmodradio.com"] [uri "/sftp-config.json"] [unique_id "aiqs57OIjnhOZXaVpzrBjwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
nzhost.co.nz
2026-06-11 11:18:15
(1 day ago)
$f2bV_matches
Hacking
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-11 11:17:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.156.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.156.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 07:17:04.249099 2026] [security2:error] [pid 2845:tid 2865] [client 104.28.156.216:40678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trident-environmental.com"] [uri "/sftp-config.json"] [unique_id "aiqZMNoYbzbC7XRbABsrZAAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
MM-bot
2026-06-11 11:03:14
(1 day ago)
URL-probe: HTTP/1.1 GET request on /sftp-config.json (2026-06-11 13:03:14 UTC+2)
Web App Attack
Hacking
π¬π§
Yosi
2026-06-11 10:04:55
(1 day ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-05-29 07:42:08
(2 weeks ago)
[redacted] 104.28.156.216 - - [29/May/2026:09:41:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 104.28.156.216 - - [29/May/2026:09:41:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.1; http://site75518806.com"
[redacted] 104.28.156.216 - - [29/May/2026:09:41:35 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 104.28.156.216 - - [29/May/2026:09:41:45 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 104.28.156.216 - - [29/May/2026:09:41:56 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 104.28.156.216 - - [29/May/2026:09:42:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
π§πͺ
cmbplf
2026-05-15 08:37:52
(4 weeks ago)
1.881 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
Anonymous
2026-05-04 17:16:57
(1 month ago)
104.28.156.216 (CA/Canada/-)
Brute-Force
Anonymous
2026-05-04 16:31:00
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-postfix jail
Brute-Force
π¦πΊ
MAGIC
2026-05-02 01:48:38
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-02 00:04:43
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.28.156.216 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.156.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 20:04:39.501117 2026] [security2:error] [pid 16854:tid 16854] [client 104.28.156.216:59130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grieve.tv"] [uri "/sftp-config.json"] [unique_id "afU_l6eGVgqSg1HT9mglrQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ
MWA SOC
2026-05-01 23:58:24
(1 month ago)
Hacking
Anonymous
2026-04-29 04:31:36
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-postfix jail
Brute-Force