πΊπΈ
TPI-Abuse
2026-07-25 17:43:18
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 13:43:10.400874 2026] [security2:error] [pid 1346134:tid 1346134] [client 104.64.212.14:61390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yournamehereonline.net"] [uri "/sftp-config.json"] [unique_id "amT1rpCrjRuWXl73fAHqCQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 16:32:26
(15 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π²π½
octageeks.com
2026-07-25 04:18:18
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
π¦πΊ
paulshipley.com.au
2026-07-25 03:55:24
(1 day ago)
[Sat Jul 25 13:55:23.583491 2026] [security2:error] [pid 737785] [client 104.64.212.14:51404] [clien ...
show more
[Sat Jul 25 13:55:23.583491 2026] [security2:error] [pid 737785] [client 104.64.212.14:51404] [client 104.64.212.14] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/sftp-config.json"] [unique_id "amQzq468cUExrZTWTqWOWQAAAAM"]
...
show less
Web App Attack
π«π·
lechat
2026-07-25 03:35:26
(1 day ago)
2026-07-25T03:35:26.274382+0000 inbound port scan detected by Suricata. src=104.64.212.14:57050 dst= ...
show more
2026-07-25T03:35:26.274382+0000 inbound port scan detected by Suricata. src=104.64.212.14:57050 dst=51.68.231.122:80 proto=TCP. signature="ET SCAN SFTP/FTP Password Exposure via sftp-config.json" category="Attempted Information Leak" sid=2015940 reason=scan_signature.
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-07-25 03:19:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 23:19:43.424053 2026] [security2:error] [pid 1085766:tid 1085766] [client 104.64.212.14:50925] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scc1.us"] [uri "/parked/sftp-config.json"] [unique_id "amQrT667D6ChcxyAfUkXkAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
Valhalla
2026-07-25 03:03:38
(1 day ago)
/sftp-config.json
Hacking
Web App Attack
π©πͺ
big-cloud.nl
2026-07-25 02:27:18
(1 day ago)
Try to access /.vscode/sftp.json
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 02:05:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 22:05:52.440765 2026] [security2:error] [pid 336706:tid 336706] [client 104.64.212.14:52767] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "worshipconcert.com"] [uri "/sftp-config.json"] [unique_id "amQaAEFZRSQNom6OTaaYsgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
almazick
2026-07-25 01:58:57
(1 day ago)
Fail2Ban jail window on srv1.windowrepair.us banned 104.64.212.14 after 1 attempts
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-07-25 01:55:52
(1 day ago)
[SatJul2503:55:45.3172702026][security2:error][pid3641496:tid3641537][client104.64.212.14:0]ModSecur ...
show more
[SatJul2503:55:45.3172702026][security2:error][pid3641496:tid3641537][client104.64.212.14:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"worldgoldfundltd.com\"][uri\"/sftp-config.json\"][unique_id\"amQXoahJKBRrEHh80x2IvAAAAEQ\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 01:35:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 21:35:43.471729 2026] [security2:error] [pid 1669415:tid 1669415] [client 104.64.212.14:58425] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mapleleaf-marketing.com"] [uri "/sftp-config.json"] [unique_id "amQS77T2K2D59QkE6MsktQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 01:11:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 21:11:41.638582 2026] [security2:error] [pid 1131006:tid 1131006] [client 104.64.212.14:50243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wiltoncheese.com"] [uri "/sftp-config.json"] [unique_id "amQNTe3lqGB5tqkUZEnKhwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 23:53:09
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 104.64.212.14 (104-64-212-14.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 104.64.212.14 (104-64-212-14.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 19:53:03.140091 2026] [security2:error] [pid 962748:tid 962748] [client 104.64.212.14:54230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "wilmoth.us"] [uri "/sftp-config.json"] [unique_id "amP636hVPvPHDGaylVquqwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 23:30:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.14 (104-64-212-14.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 19:30:03.542871 2026] [security2:error] [pid 1390700:tid 1390700] [client 104.64.212.14:53768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wordspectrum.com"] [uri "/sftp-config.json"] [unique_id "amP1e3fI1Onu3mZdZ1lpAwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack