🇺🇸
TPI-Abuse
2026-08-30 15:11:02
(43 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.28.252.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.252.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 11:10:56.884338 2026] [security2:error] [pid 6055:tid 6055] [client 104.28.252.180:52832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cathybermanmft.com"] [uri "/sftp-config.json"] [unique_id "apRIAJHMGIezi5dnLi41uQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-08-30 13:21:52
(2 hours ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
Anonymous
2026-08-30 04:06:04
(11 hours ago)
Trying to access config files
Web App Attack
🇩🇪
FeG Deutschland
2026-08-30 01:18:05
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 00:46:28
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.252.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.252.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 20:46:21.774963 2026] [security2:error] [pid 8162:tid 8162] [client 104.28.252.180:54898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carbtestingidaho.com"] [uri "/sftp-config.json"] [unique_id "apN9XTPxRtCvuoK77ISDpwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 23:41:10
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.252.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.252.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 19:41:04.191980 2026] [security2:error] [pid 26809:tid 26809] [client 104.28.252.180:60703] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blacksheepoffroad.com"] [uri "/sftp-config.json"] [unique_id "apNuEPSCaXzdGbH2EgRiiwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-08-29 23:17:54
(16 hours ago)
[Sun Aug 30 09:17:54.593324 2026] [security2:error] [pid 840707] [client 104.28.252.180:41101] [clie ...
show more
[Sun Aug 30 09:17:54.593324 2026] [security2:error] [pid 840707] [client 104.28.252.180:41101] [client 104.28.252.180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/sftp-config.json"] [unique_id "apNooklnSjKzwT1vmLkpZQAAAC0"]
...
show less
Web App Attack
🇳🇱
MM-bot
2026-08-29 22:22:42
(17 hours ago)
URL-probe: HTTP/1.1 GET request on /sftp-config.json (2026-08-30 00:22:42 UTC+2)
Web App Attack
Hacking
🇦🇺
2000cn.com.au
2026-08-29 21:09:28
(18 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇮
Shaik Sai Meera
2026-08-29 20:50:22
(19 hours ago)
IM360 WAF: Hidden file access
Brute-Force
🇺🇸
TPI-Abuse
2026-08-29 19:07:36
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.252.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.252.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 15:07:34.031105 2026] [security2:error] [pid 457268:tid 457300] [client 104.28.252.180:28609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chelseyrae.com"] [uri "/sftp-config.json"] [unique_id "apMt9tIP22OgrJOK8kvymwAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
bcsaba
2026-08-29 19:02:55
(20 hours ago)
Suricata: Alert - ET SCAN SFTP/FTP Password Exposure via sftp-config.json
Web App Attack
Anonymous
2026-08-29 18:45:19
(21 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇪🇸
el-brujo
2026-08-24 07:43:08
(6 days ago)
Cloudflare WAF: Request Path: /sftp-config.json Request Query: Host: elhacker.net userAgent: Mozill ...
show more
Cloudflare WAF: Request Path: /sftp-config.json Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 Action: block Source: firewallManaged ASN Description: Cloudflare, Inc. Country: KH Method: GET Timestamp: 2026-08-24T07:43:08Z ruleId: c2a2f414a67c409f90cccb6c5bba0215. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
🇧🇪
cmbplf
2026-08-23 16:36:23
(6 days ago)
149 requests with url.path *sftp.json
122 requests with url.path *config.json
Brute-Force
Bad Web Bot