๐บ๐ธ
TPI-Abuse
2026-06-15 07:18:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:18:49.741074 2026] [security2:error] [pid 8468:tid 8491] [client 152.163.110.10:42960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howiek.com"] [uri "/sftp-config.json"] [unique_id "ai-nWQ8y5aXWj-ddImKztQAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-15 05:15:11
(4 days ago)
Try to access /.vscode/sftp.json
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 05:11:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:11:28.311043 2026] [security2:error] [pid 17673:tid 17673] [client 152.163.110.10:53262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "houstontenemosunproblema.com"] [uri "/sftp-config.json"] [unique_id "ai-JgCtMSUlY3rjWAHxJggAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-14 10:22:28
(5 days ago)
[SunJun1412:22:21.3414552026][security2:error][pid1715523:tid1715745][client152.163.110.10:0]ModSecu ...
show more
[SunJun1412:22:21.3414552026][security2:error][pid1715523:tid1715745][client152.163.110.10:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\\\\\\\\.vscode/\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1189\"][id\"350593\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-Dataleakage-attempttoaccessstoredvscodepasswords\"][severity\"CRITICAL\"][hostname\"hosting-ticino-svizzera.ch\"][uri\"/.vscode/sftp.json\"][unique_id\"ai6A3ZEiNRy4Iex4MdcB2AAAAI4\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 18:24:46
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 14:24:38.962618 2026] [security2:error] [pid 7494:tid 7494] [client 152.163.110.10:29828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homewaterproofing.com"] [uri "/sftp-config.json"] [unique_id "ai2gZv4pTFbjI_SFHW-fSgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-13 02:46:56
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-06-12 23:08:01
(1 week ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-06-12 22:07:02
(1 week ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 06:52:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 02:52:41.482832 2026] [security2:error] [pid 5741:tid 5741] [client 152.163.110.10:46816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hillconsultants.com"] [uri "/sftp-config.json"] [unique_id "aiusuWo0PksPKU2_VeJHIQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 02:54:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 22:54:04.057867 2026] [security2:error] [pid 5404:tid 5404] [client 152.163.110.10:48880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "high5-vr.com"] [uri "/sftp-config.json"] [unique_id "ait0zJzdcv3zcgw-mgaBogAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 00:23:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 20:23:31.382322 2026] [security2:error] [pid 5080:tid 5080] [client 152.163.110.10:54020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hi-niemczuras.net"] [uri "/sftp-config.json"] [unique_id "aitRg06RMj7DhhtPpI-4ugAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-11 19:35:53
(1 week ago)
100 requests with url.path *sftp.json
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-11 17:15:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 13:15:06.456429 2026] [security2:error] [pid 5701:tid 5701] [client 152.163.110.10:31042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hertzan.com"] [uri "/sftp-config.json"] [unique_id "airtGut4RLOQr3dCPDn1UAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 12:31:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.163.110.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 08:31:08.740673 2026] [security2:error] [pid 25393:tid 25393] [client 152.163.110.10:39814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "henryweb.net"] [uri "/sftp-config.json"] [unique_id "aiqqjGbAnuGL87LrPsSbHgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-06-11 05:46:40
(1 week ago)
Scanning for exploits - /.vscode/sftp.json
Web App Attack