๐ฉ๐ช
bescared
2026-07-21 10:59:59
(2 days ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 08:59:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 135.235.218.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 135.235.218.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 04:59:34.947012 2026] [security2:error] [pid 16615:tid 16615] [client 135.235.218.229:62110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cnwire.com"] [uri "/prevlaravel/sftp-config.json"] [unique_id "al809oNysDfJX-3hkTQohgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
alessio loto
2026-07-21 07:50:55
(2 days ago)
WAF Detection: Security_Scanner_Blocked (High Risk IP). AI Confirmed Attack Payload.
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-07-21 07:28:56
(2 days ago)
cloudlinux2 fail2ban: 2026-07-21 09:23:54,614 fail2ban.filter [1927]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-21 09:23:54,614 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 171.76.108.71 - 2026-07-21 09:23:54cloudlinux2 fail2ban: 2026-07-21 09:24:56,326 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 43.203.254.38 - 2026-07-21 09:24:55cloudlinux2 fail2ban: 2026-07-21 09:24:58,704 fail2ban.actions [1927]: NOTICE [plesk-modsecurity] Unban 103.171.52.58cloudlinux2 fail2ban: 2026-07-21 09:25:15,834 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 193.19.109.233 - 2026-07-21 09:25:15cloudlinux2 fail2ban: 2026-07-21 09:25:56,364 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 173.239.214.150 - 2026-07-21 09:25:56cloudlinux2 fail2ban: 2026-07-21 09:27:41,610 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 103.8.114.42 - 2026-07-21 09:27:41cloudlinux2 fail2ban: 2026-07-21 09:28:32,980 fail2ban.actions [1927]: NOTICE [plesk-modsecurity] Ban 135.235.218.229cloudlinux2 fail2ban: 2026-07-21 09:28:33,1
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 07:18:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 135.235.218.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 135.235.218.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 03:18:21.433206 2026] [security2:error] [pid 2564329:tid 2564329] [client 135.235.218.229:64899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barkdull.org"] [uri "/sftp-config.json"] [unique_id "al8dPdEXVcayUNXfgDylOgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dwmp
2026-07-21 05:54:21
(2 days ago)
[21/Jul/2026:07:54:19.725415 +0200] al8Ji0n4V8yhD2WnSg8a5gAAAAk 135.235.218.229 56918 38.242.227.117 ...
show more
[21/Jul/2026:07:54:19.725415 +0200] al8Ji0n4V8yhD2WnSg8a5gAAAAk 135.235.218.229 56918 38.242.227.117 7081
[21/Jul/2026:07:54:19.783102 +0200] al8Ji0n4V8yhD2WnSg8a5wAAAAE 135.235.218.229 56924 38.242.227.117 7081
[21/Jul/2026:07:54:20.358316 +0200] al8JjA@wsZ5MLaUBlC@3KQAAAIA 135.235.218.229 56926 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-21 05:49:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 135.235.218.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 135.235.218.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 01:48:56.862952 2026] [security2:error] [pid 3278754:tid 3278860] [client 135.235.218.229:53410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aafm.org"] [uri "/prevlaravel/sftp-config.json"] [unique_id "al8ISFHO6-rQ6WWmgfnf_AAAAhI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
lufi
2026-07-21 05:30:57
(2 days ago)
2026-07-21T07:30:56+02:00 lufischer04 ids442 2026-07-21 07:30:56 135.235.218.229: blacklistedPath: / ...
show more
2026-07-21T07:30:56+02:00 lufischer04 ids442 2026-07-21 07:30:56 135.235.218.229: blacklistedPath: /sftp-config.json
...
show less
Web Spam
Brute-Force
Hacking
Web App Attack
Anonymous
2026-07-20 19:10:59
(3 days ago)
"GET /prevlaravel/sftp-config.json HTTP/1.1"
Hacking
Web App Attack
Anonymous
2026-07-20 18:02:06
(3 days ago)
Web attack
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-07-20 17:55:32
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 135.235.218.229 (IN/India/-): N in the last X s ...
show more
(mod_security) mod_security (id:949110) triggered by 135.235.218.229 (IN/India/-): N in the last X secs
show less
Web App Attack
Anonymous
2026-07-20 17:25:12
(3 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-20 17:13:20
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ต๐ฑ
nakordoni.eu
2026-07-20 17:00:03
(3 days ago)
Blocked by nakordoni.eu automated security: vulnerability scanner / probe attack. Jail: nakordoni-se ...
show more
Blocked by nakordoni.eu automated security: vulnerability scanner / probe attack. Jail: nakordoni-security-probe, 3 matches. ISP: Microsoft Limited (IN), Usage: Data Center/Web Hosting/Transit. Prior AbuseIPDB score at ban time: 63/100.
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-07-20 16:41:44
(3 days ago)
[Mon Jul 20 18:41:44.116629 2026] [security2:error] [pid 1397188:tid 1397204] [client 135.235.218.22 ...
show more
[Mon Jul 20 18:41:44.116629 2026] [security2:error] [pid 1397188:tid 1397204] [client 135.235.218.229:0] [client 135.235.218.229] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mmn.ca"] [uri "/prevlaravel/sftp-config.json"] [unique_id "al5PyHKynP17FcitFbkhyAAAAM4"], referer: http://mmn.ca/prevlaravel/sftp-config.json
[Mon Jul 20 18:41:44.144164 2026] [security2:error] [pid 1397188:tid 1397213] [client 135.235.218.229:0] [client 135.235.218.229] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly
...
show less
Web App Attack
Bad Web Bot