π©πͺ
filstal.org
2026-07-25 10:09:01
(2 hours ago)
Persistent bad bot: repeated automated abuse detected
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 07:24:52
(5 hours ago)
(caddyscan) Scanner path probe from 104.64.212.46 (SG/Singapore/104-64-212-46.ip.linodeusercontent.c ...
show more
(caddyscan) Scanner path probe from 104.64.212.46 (SG/Singapore/104-64-212-46.ip.linodeusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.64.212.46 - - [25/Jul/2026:07:22:21 +0000] "GET /.vscode/sftp.json HTTP/1.1"
[REDACTED] 200 2627 104.64.212.46 - - [25/Jul/2026:07:24:16 +0000] "GET /.vscode/sftp.json HTTP/1.1"
[REDACTED] 200 2627 104.64.212.46 - - [25/Jul/2026:07:24:33 +0000] "GET /.vscode/sftp.json HTTP/1.1"
[REDACTED] 200 2627 104.64.212.46 - - [25/Jul/2026:07:24:44 +0000] "GET /.vscode/sftp.json HTTP/1.1"
[REDACTED] 200 2627 104.64.212.46 - - [25/Jul/2026:07:24:51 +0000] "GET /.vscode/sftp.json HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-07-25 05:08:28
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 01:08:21.885613 2026] [security2:error] [pid 3047754:tid 3047754] [client 104.64.212.46:49322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wedemandavote.com"] [uri "/sftp-config.json"] [unique_id "amRExbUFO4oZz6YPfAwpFwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
ππΊ
DumaNet
2026-07-25 04:46:00
(8 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Jul 24. 19:13:08
Source IP: 104.64 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Jul 24. 19:13:08
Source IP: 104.64.212.46
Portion of the log(s):
104.64.212.46 - [24/Jul/2026:19:13:08 +0200] "GET /.vscode/sftp.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
104.64.212.46 - [24/Jul/2026:19:13:07 +0200] "GET /sftp-config.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
104.64.212.46 - [24/Jul/2026:19:12:28 +0200] "GET /.vscode/sftp.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
104.64.212.46 - [24/Jul/2026:19:12:27 +0200] "GET /sftp-config.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
104.64.212.46 - [24/Jul/2026:19:11:28 +0200] "GET /.vscode/sftp.json HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Web App Attack
π©πͺ
filstal.org
2026-07-25 04:41:08
(8 hours ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 04:19:57
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 00:19:51.533273 2026] [security2:error] [pid 1443676:tid 1443676] [client 104.64.212.46:58657] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webtony.net"] [uri "/sftp-config.json"] [unique_id "amQ5Z5zNgzoruPMPfZPLMQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Kimax
2026-07-25 04:16:49
(8 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-25 03:29:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 23:29:56.431985 2026] [security2:error] [pid 1034212:tid 1034212] [client 104.64.212.46:61630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webserviceswest.com"] [uri "/sftp-config.json"] [unique_id "amQttNkQrhsfo3sBgQEwEQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
s@ch@
2026-07-25 02:30:01
(10 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
Anonymous
2026-07-25 02:21:47
(10 hours ago)
(caddyscan) Scanner path probe from 104.64.212.46 (SG/Singapore/104-64-212-46.ip.linodeusercontent.c ...
show more
(caddyscan) Scanner path probe from 104.64.212.46 (SG/Singapore/104-64-212-46.ip.linodeusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 104.64.212.46 - - [25/Jul/2026:02:20:15 +0000] "GET /.vscode/sftp.json HTTP/1.1"
[REDACTED] 200 2627 104.64.212.46 - - [25/Jul/2026:02:20:19 +0000] "GET /.vscode/sftp.json HTTP/1.1"
[REDACTED] 200 2627 104.64.212.46 - - [25/Jul/2026:02:21:25 +0000] "GET /.vscode/sftp.json HTTP/1.1"
[REDACTED] 200 2627 104.64.212.46 - - [25/Jul/2026:02:21:35 +0000] "GET /.vscode/sftp.json HTTP/1.1"
[REDACTED] 200 2627 104.64.212.46 - - [25/Jul/2026:02:21:43 +0000] "GET /.vscode/sftp.json HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-07-25 02:15:46
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 22:15:38.814092 2026] [security2:error] [pid 757637:tid 757637] [client 104.64.212.46:55051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weddingmusicguitar.com"] [uri "/sftp-config.json"] [unique_id "amQcSjFlOmB-OD3rqjtJbwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 01:57:27
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 21:57:22.196628 2026] [security2:error] [pid 666014:tid 666014] [client 104.64.212.46:64284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xcarsubscription.com"] [uri "/sftp-config.json"] [unique_id "amQYAvSMioFVhZpanVg8TQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
thetomtaylor.co.uk
2026-07-24 23:08:01
(13 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
thetomtaylor.co.uk
2026-07-24 22:07:02
(14 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 21:18:10
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.64.212.46 (104-64-212-46.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 17:18:04.017499 2026] [security2:error] [pid 4182249:tid 4182249] [client 104.64.212.46:59135] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wea-inc.com"] [uri "/sftp-config.json"] [unique_id "amPWjLcHjEJVfP3icZygvQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack