๐บ๐ธ
TPI-Abuse
2026-09-01 14:52:23
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 139.162.27.211 (139-162-27-211.ip.linodeusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 139.162.27.211 (139-162-27-211.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:52:16.169019 2026] [security2:error] [pid 4930:tid 4930] [client 139.162.27.211:54182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diepeveen.net"] [uri "/sftp-config.json"] [unique_id "apbmoF2e8Sm15Q0sOixbSwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:28:45
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 139.162.27.211 (139-162-27-211.ip.linodeusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 139.162.27.211 (139-162-27-211.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:28:39.985941 2026] [security2:error] [pid 5359:tid 5359] [client 139.162.27.211:50061] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dildog.com"] [uri "/sftp-config.json"] [unique_id "apbTBx5lQNcdW6TJWQ0HUgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-09-01 10:06:49
(5 hours ago)
WebAttack or semilar from 139.162.27.211
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:31:57
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 139.162.27.211 (139-162-27-211.ip.linodeusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 139.162.27.211 (139-162-27-211.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:31:52.510507 2026] [security2:error] [pid 3681:tid 3681] [client 139.162.27.211:54396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "discountphotogifts.com"] [uri "/sftp-config.json"] [unique_id "apZHKJhUne9EzM8kh8stLwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 03:25:05
(11 hours ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 02:55:06
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:04:18
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 139.162.27.211 (139-162-27-211.ip.linodeusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 139.162.27.211 (139-162-27-211.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:04:12.572548 2026] [security2:error] [pid 4485:tid 4485] [client 139.162.27.211:60026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digbiellc.com"] [uri "/sftp-config.json"] [unique_id "apYynB6VzRi_A6cVxYDOcQAAAGk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 00:43:12
(14 hours ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-31 20:15:02
(18 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-31 19:47:20
(19 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
LRob
2026-08-31 15:00:19
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.vscode/sftp.json | 2026-08-31 15:00 UTC
show less
Hacking
Web App Attack