๐บ๐ธ
TPI-Abuse
2026-09-16 07:24:07
(15 minutes ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:24:03.892766 2026] [security2:error] [pid 2224831:tid 2224831] [client 147.93.139.252:53716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adamscott.us"] [uri "/sftp-config.json"] [unique_id "aqpEE2-DWWsdFBn9m0zWCAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-16 06:38:57
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-16 08:35:11,874 fail2ban.filter [1818]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-16 08:35:11,874 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 78.180.58.17 - 2026-09-16 08:35:11cloudlinux2 fail2ban: 2026-09-16 08:35:39,558 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 147.93.139.252 - 2026-09-16 08:35:39cloudlinux2 fail2ban: 2026-09-16 08:36:15,104 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 78.180.58.17 - 2026-09-16 08:36:15cloudlinux2 fail2ban: 2026-09-16 08:36:47,083 fail2ban.filter [1818]: INFO [recidive] Found 104.234.53.15 - 2026-09-16 08:36:46cloudlinux2 fail2ban: 2026-09-16 08:36:46,381 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 104.234.53.15 - 2026-09-16 08:36:46cloudlinux2 fail2ban: 2026-09-16 08:36:45,461 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 104.234.53.15 - 2026-09-16 08:36:45cloudlinux2 fail2ban: 2026-09-16 08:36:46,946 fail2ban.actions [1818]: NOTICE [plesk-wordpress] Ban 104.234.53.15cloudlinux2 fail2ban: 2026-09-16 08
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 02:59:50
(4 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /.vscode/sftp.json (+1 more) | ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /.vscode/sftp.json (+1 more) | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 (+1 more) | 2026-09-16 02:59 UTC
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:31:47
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:31:39.585070 2026] [security2:error] [pid 9034:tid 9034] [client 147.93.139.252:46112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "albertmassaad.com"] [uri "/sftp-config.json"] [unique_id "aqnxe9hEYiKhSZfH8rZN4wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:15:51
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:15:44.749054 2026] [security2:error] [pid 18783:tid 18783] [client 147.93.139.252:53406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "empratec.com"] [uri "/sftp-config.json"] [unique_id "aqnfsHruLVUpqJDmJNwh_AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
ycoskun41
2026-09-15 23:32:02
(8 hours ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-15 21:30:01
(10 hours ago)
SPAM - Bruteforce Attack - DDOS 5
Email Spam
Brute-Force
๐บ๐ธ
nyt
2026-09-15 15:39:25
(15 hours ago)
Deploy Config Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 15:17:06
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:16:58.941173 2026] [security2:error] [pid 11178:tid 11178] [client 147.93.139.252:54828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pembrokefinance.com"] [uri "/sftp-config.json"] [unique_id "aqlhal5HNsfKElhCQOgFHwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-09-15 14:35:01
(17 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-15 13:53:41
(17 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local blo ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local block policy. Evidence: High Abuse + Suspicion (62, Abuse: 54)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 13:27:19
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:27:14.665321 2026] [security2:error] [pid 15823:tid 15823] [client 147.93.139.252:60668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americancryonics.org"] [uri "/sftp-config.json"] [unique_id "aqlHslpsqkvi72YGVmCCewAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 03:45:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 23:45:28.711805 2026] [security2:error] [pid 28152:tid 28152] [client 147.93.139.252:45806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "husman.es"] [uri "/sftp-config.json"] [unique_id "aqi_WLOlVunzoD_NHK3lEwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
ketovoila.pl
2026-09-15 01:57:15
(1 day ago)
ketovoila.pl web app secret/repository scan: hits=2; unique_paths=2; sample_paths=/.vscode/sftp.json ...
show more
ketovoila.pl web app secret/repository scan: hits=2; unique_paths=2; sample_paths=/.vscode/sftp.json; UA="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"; window=2026-09-15T01:57:15Z..2026-09-15T01:57:15Z HTTP methods: GET (2).
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 23:54:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 147.93.139.252 (vmi3031485.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 19:53:57.878661 2026] [security2:error] [pid 17324:tid 17324] [client 147.93.139.252:60470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eurosoni.com"] [uri "/sftp-config.json"] [unique_id "aqiJFUBY4shUWwNFUUL-uwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack