๐น๐ท
oalver
2026-08-24 16:21:51
(12 hours ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /.vscode/sftp.json (HTTP 301). First seen: 2026-08-24. Risk score: 30/100.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 11:51:26
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.230.131.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 157.230.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:51:19.640933 2026] [security2:error] [pid 27276:tid 27276] [client 157.230.131.30:53282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noviasaltovacio.com"] [uri "/sftp-config.json"] [unique_id "aowwN6Lym_E2-1tSBCPTPwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-24 08:18:30
(20 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: \.vscode (Match: .vscode)
show less
Hacking
Web App Attack
๐บ๐ธ
SX Communications
2026-08-24 07:49:41
(20 hours ago)
Blocked abusive HTTP application-layer DoS / botnet traffic from 157.230.131.30: traffic from this a ...
show more
Blocked abusive HTTP application-layer DoS / botnet traffic from 157.230.131.30: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
๐ฉ๐ช
big-cloud.nl
2026-08-24 05:15:01
(23 hours ago)
Try to access /arrangementen/.vscode/sftp.json
Web App Attack
๐ธ๐ช
SkyDancer
2026-08-24 04:44:48
(23 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐บ๐ธ
moppetto
2026-08-24 03:08:05
(1 day ago)
VSCode credential scraping; GET /.vscode/sftp.json
Bad Web Bot
๐ช๐ธ
el-brujo
2026-08-23 23:57:47
(1 day ago)
24/Aug/2026:01:57:46.730344 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
24/Aug/2026:01:57:46.730344 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 157.230.131.30] ModSecurity: Warning. Matched phrase "/sftp-config.json" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /sftp-config.json found within REQUEST_FILENAME: /sftp-config.json"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "hostench.eu"] [uri "/sftp-config.json"] [unique_id "aouI-hAqsgCS3DGEg4ZofQAH4j4"]
...
show less
Hacking
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-08-23 23:34:51
(1 day ago)
$f2bV_matches
Hacking
Brute-Force
๐ซ๐ฎ
paissangroup
2026-08-23 17:35:58
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 14:59:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.230.131.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 157.230.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:59:08.185178 2026] [security2:error] [pid 24925:tid 24925] [client 157.230.131.30:63428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gcmmortgage.com"] [uri "/sftp-config.json"] [unique_id "aosKvIIwU8MaIJdCfSTMmgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-08-23 14:11:21
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ท๐ด
clauss
2026-08-23 13:06:59
(1 day ago)
157.230.131.30 - - [23/Aug/2026:16:06:57 +0300] "GET /.vscode/sftp.json HTTP/2.0" 301 0 "-" "Mozilla ...
show more
157.230.131.30 - - [23/Aug/2026:16:06:57 +0300] "GET /.vscode/sftp.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
157.230.131.30 - - [23/Aug/2026:16:06:59 +0300] "GET /.vscode/sftp.json HTTP/2.0" 404 11136 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 05:56:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.230.131.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 157.230.131.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:56:28.213501 2026] [security2:error] [pid 22107:tid 22107] [client 157.230.131.30:53950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laydox.com"] [uri "/sftp-config.json"] [unique_id "aoqLjJDGQXlmaBQEd_XISwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-23 05:05:29
(1 day ago)
Request Overload (449)
Brute-Force
Web App Attack