๐ฉ๐ช
paissangroup
2026-07-24 23:02:37
(10 minutes ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 18:10:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 152.42.165.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 152.42.165.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 14:09:54.171887 2026] [security2:error] [pid 2196969:tid 2196969] [client 152.42.165.47:60008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radar24hrs.com"] [uri "/sftp-config.json"] [unique_id "amOqctN4UxrWJ5Z2tMeujwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-24 18:08:02
(5 hours ago)
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [ice01,ice02]
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-24 16:07:02
(7 hours ago)
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [mx01,wa01,wa02]
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-07-24 15:05:18
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-24 09:50:02
(13 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 05:38:00
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 152.42.165.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 152.42.165.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:37:57.383510 2026] [security2:error] [pid 3404014:tid 3404014] [client 152.42.165.47:60395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epicjellyfish.com"] [uri "/sftp-config.json"] [unique_id "amL6NfGEuC4HbQNoSgHGpgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 04:10:25
(19 hours ago)
152.42.165.47 - - [23/Jul/2026:23:10:20 -0500] "GET /sftp-config.json HTTP/2.0" 301 249 "-" "Mozilla ...
show more
152.42.165.47 - - [23/Jul/2026:23:10:20 -0500] "GET /sftp-config.json HTTP/2.0" 301 249 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
152.42.165.47 - - [23/Jul/2026:23:10:20 -0500] "GET /sftp-config.json HTTP/2.0" 404 33719 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
152.42.165.47 - - [23/Jul/2026:23:10:24 -0500] "GET /.sftp-config.json HTTP/2.0" 301 250 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-07-24 03:57:23
(19 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ซ๐ฎ
as211431.net
2026-07-24 01:45:33
(21 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.vscode/ftp-sync.json
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ญ
4server
2026-07-23 23:38:51
(23 hours ago)
[FriJul2401:38:47.8930802026][security2:error][pid817546:tid817806][client152.42.165.47:0]ModSecurit ...
show more
[FriJul2401:38:47.8930802026][security2:error][pid817546:tid817806][client152.42.165.47:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"executivekotech.com\"][uri\"/sftp-config.json\"][unique_id\"amKmB2wKA8RdNDHB_yKENQAAAIo\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 17:14:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 152.42.165.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 152.42.165.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:14:17.351549 2026] [security2:error] [pid 3067654:tid 3067654] [client 152.42.165.47:61286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.exhaustthelimits.org"] [uri "/sftp-config.json"] [unique_id "amJL6cyc3O30QbfuHAo2CQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-07-23 17:00:28
(1 day ago)
[23/Jul/2026:19:00:26 +0200] 178482602615.229833 152.42.165.47 61365 217.154.7.177 80
[23/Jul/2026:1 ...
show more
[23/Jul/2026:19:00:26 +0200] 178482602615.229833 152.42.165.47 61365 217.154.7.177 80
[23/Jul/2026:19:00:26 +0200] 178482602623.515039 152.42.165.47 61473 217.154.7.177 80
[23/Jul/2026:19:00:27 +0200] 178482602790.542691 152.42.165.47 61564 217.154.7.177 80
[23/Jul/2026:19:00:27 +0200] 178482602772.986108 152.42.165.47 61684 217.154.7.177 80
[23/Jul/2026:19:00:28 +0200] 178482602867.344201 152.42.165.47 61773 217.154.7.177 80
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 12:55:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 152.42.165.47 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 152.42.165.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 08:55:29.743001 2026] [security2:error] [pid 2235432:tid 2235432] [client 152.42.165.47:61579] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "empratec.com"] [uri "/sftp-config.json"] [unique_id "amIPQWCQvhoF_BdFh4f5MQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 12:35:12
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host