🇩🇪
4server
2026-09-15 06:31:51
(4 minutes ago)
[TueSep1508:31:45.9425282026][security2:error][pid2870007:tid2870147][client147.93.139.250:0]ModSecu ...
show more
[TueSep1508:31:45.9425282026][security2:error][pid2870007:tid2870147][client147.93.139.250:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\\\\\\\\.vscode/\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1189\"][id\"350593\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-Dataleakage-attempttoaccessstoredvscodepasswords\"][severity\"CRITICAL\"][hostname\"elyon2.ch\"][uri\"/.vscode/sftp.json\"][unique_id\"aqjmUX7fz63qvpejisVnIQAAARY\"]
show less
Port Scan
Brute-Force
Web App Attack
🇫🇷
ELYAZ
2026-09-15 06:27:56
(8 minutes ago)
(y3) Failed access -byebye- from 147.93.139.250 (US/United States/vmi3031483.contaboserver.net): (C ...
show more
(y3) Failed access -byebye- from 147.93.139.250 (US/United States/vmi3031483.contaboserver.net): (CF_ENABLE)
show less
Hacking
🇫🇷
Baking333
2026-09-15 05:28:53
(1 hour ago)
[redacted] 147.93.139.250 - - [15/Sep/2026:06:28:52 +0100] "GET /[redacted] HTTP/1.1" 302 6753 0/441 ...
show more
[redacted] 147.93.139.250 - - [15/Sep/2026:06:28:52 +0100] "GET /[redacted] HTTP/1.1" 302 6753 0/44125 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" 443 [redacted] 147.93.139.250 - - [15/Sep/2026:06:28:52 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 6753 0/42926 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" 443
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 03:55:43
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 23:55:40.145315 2026] [security2:error] [pid 28510:tid 28510] [client 147.93.139.250:55494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elpasoheroes.com"] [uri "/sftp-config.json"] [unique_id "aqjBvHWWNcSiNV53yrIs3QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 02:24:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 22:24:25.394889 2026] [security2:error] [pid 14482:tid 14482] [client 147.93.139.250:42004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elmarwamarine.com"] [uri "/sftp-config.json"] [unique_id "aqisWe-aundiAF6eo-bVwwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 01:22:38
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 21:22:35.014241 2026] [security2:error] [pid 20618:tid 20618] [client 147.93.139.250:58212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ellesorority.com"] [uri "/sftp-config.json"] [unique_id "aqid28YjEu8RypUfgAIZOgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 00:52:57
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 20:52:52.665593 2026] [security2:error] [pid 20940:tid 20940] [client 147.93.139.250:35922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ellavandeven.com"] [uri "/sftp-config.json"] [unique_id "aqiW5P0h-jvtM6A5RggpBAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nyt
2026-09-15 00:48:12
(5 hours ago)
Deploy Config Probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 23:53:23
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 19:53:17.321490 2026] [security2:error] [pid 21036:tid 21036] [client 147.93.139.250:38142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elizabethkwon.com"] [uri "/sftp-config.json"] [unique_id "aqiI7RVva7btUh1SBtLixQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 22:49:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 18:49:16.072099 2026] [security2:error] [pid 3414:tid 3430] [client 147.93.139.250:49902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eliteproductions.tv"] [uri "/sftp-config.json"] [unique_id "aqh57ClQQ6q7fgcGhAtF7AAAAss"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 21:14:11
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 17:14:04.204978 2026] [security2:error] [pid 8178:tid 8178] [client 147.93.139.250:34214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eliseheritage.com"] [uri "/sftp-config.json"] [unique_id "aqhjnI2qdY-mbDgeuZRFJwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-14 21:03:25
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 20:28:22
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.250 (vmi3031483.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 16:28:17.256635 2026] [security2:error] [pid 30102:tid 30102] [client 147.93.139.250:35272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elimer.com.ve"] [uri "/sftp-config.json"] [unique_id "aqhY4YX07hWkAHL4XAxDhQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-14 20:26:27
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇮🇹
CoreTech srl
2026-09-14 20:23:56
(10 hours ago)
cloudlinux2 fail2ban: 2026-09-14 22:18:49,546 fail2ban.filter [1908]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-14 22:18:49,546 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 102.220.158.200 - 2026-09-14 22:18:49cloudlinux2 fail2ban: 2026-09-14 22:18:51,499 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 147.93.139.250 - 2026-09-14 22:18:51cloudlinux2 fail2ban: 2026-09-14 22:19:32,654 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 23.239.29.46 - 2026-09-14 22:19:32cloudlinux2 fail2ban: 2026-09-14 22:19:58,378 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Unban 178.220.13.106cloudlinux2 fail2ban: 2026-09-14 22:20:52,271 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 85.172.90.158 - 2026-09-14 22:20:51cloudlinux2 fail2ban: 2026-09-14 22:21:34,080 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 85.172.90.158 - 2026-09-14 22:21:34cloudlinux2 fail2ban: 2026-09-14 22:21:56,516 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Ban 85.172.90.158cloudlinux2 fail2ban: 2026-09-14 22:21
show less
Web App Attack