๐บ๐ธ
TPI-Abuse
2026-08-24 05:39:30
(34 minutes ago)
(mod_security) mod_security (id:210492) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 01:39:20.837050 2026] [security2:error] [pid 8126:tid 8126] [client 167.172.115.163:50935] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "juncurryahn.com"] [uri "/sftp-config.json"] [unique_id "aovZCJr4JpJv_iTQRZEEJwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HERA - Operations
2026-08-24 04:45:04
(1 hour ago)
club-herrmann - searching for vulnerable scripts: sftp.json 2026/08/24 06:45:04
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-24 03:33:57
(2 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: \.vscode (Match: .vscode)
show less
Hacking
Web App Attack
๐บ๐ธ
mawan
2026-08-24 02:31:30
(3 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 23:18:57
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 19:18:49.390152 2026] [security2:error] [pid 20190:tid 20190] [client 167.172.115.163:61481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srich.com"] [uri "/sftp-config.json"] [unique_id "aot_2SED736aiE2p2DgFBwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-23 19:05:08
(11 hours ago)
Too many Status 40X (11)
Request Overload (601)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 18:26:52
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 14:26:46.499941 2026] [security2:error] [pid 21054:tid 21080] [client 167.172.115.163:64746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peluqueriabuhos.com"] [uri "/sftp-config.json"] [unique_id "aos7ZkDnExc5Y6HojGT3vgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-08-23 18:25:14
(11 hours ago)
sle-17 : Block hidden directories=>/.vscode/sftp.json(/)
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-23 16:43:49
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 12:43:42.815553 2026] [security2:error] [pid 21099:tid 21099] [client 167.172.115.163:51143] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agupgrade.net"] [uri "/sftp-config.json"] [unique_id "aosjPu9KHH9JonWuqHPjgQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 14:58:10
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:58:04.756093 2026] [security2:error] [pid 537:tid 537] [client 167.172.115.163:63744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wearywillie.com"] [uri "/sftp-config.json"] [unique_id "aosKfHfOisUf1tCTYR_6WAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-08-23 11:17:34
(18 hours ago)
doe-17 : Block hidden directories=>/.vscode/sftp.json(/)
Hacking
๐ง๐ช
cmbplf
2026-08-23 10:42:44
(19 hours ago)
143 requests with url.path *config.json
Brute-Force
Bad Web Bot
๐ฌ๐ง
consul.to
2026-08-23 09:05:21
(21 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
LRob
2026-08-23 07:02:07
(23 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /sftp-config.json (+1 more)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 01:31:10
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 167.172.115.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 21:31:05.880735 2026] [security2:error] [pid 18113:tid 18113] [client 167.172.115.163:61270] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "quailmesa.com"] [uri "/sftp-config.json"] [unique_id "aopNWc9HBNniICjQSrptZgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack