Anonymous
2026-08-31 16:32:08
(2 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐จ๐ญ
4server
2026-08-31 16:07:16
(3 hours ago)
[MonAug3118:07:11.7164782026][security2:error][pid3466358:tid3466531][client170.101.96.53:0]ModSecur ...
show more
[MonAug3118:07:11.7164782026][security2:error][pid3466358:tid3466531][client170.101.96.53:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\\\\\\\\.vscode/\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1189\"][id\"350593\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-Dataleakage-attempttoaccessstoredvscodepasswords\"][severity\"CRITICAL\"][hostname\"inserzioniticino.ch\"][uri\"/.vscode/sftp.json\"][unique_id\"apWmr6tuhI2xJY9-Bz4nvwAAANI\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-31 14:42:42
(4 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: \.vscode (Match: .vscode)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 14:30:26
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 10:30:17.887936 2026] [security2:error] [pid 9225:tid 9225] [client 170.101.96.53:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antitribu.com"] [uri "/sftp-config.json"] [unique_id "apWP-eyb1CcqdyCtoeCAzwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-31 13:01:50
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /sftp-config.json (+1 more) | 2026-08-31 13:01 UTC
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-31 11:45:32
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".vscode" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-31 10:20:20
(9 hours ago)
Try to access /.vscode/sftp.json
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-31 09:25:50
(10 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
filstal.org
2026-08-31 09:08:15
(10 hours ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-08-31 08:23:44
(11 hours ago)
2026/08/31 08:23:24 [error] 2115101#2115101: *112168 [client 170.101.96.53] ModSecurity: Access deni ...
show more
2026/08/31 08:23:24 [error] 2115101#2115101: *112168 [client 170.101.96.53] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "ingelmart.com"] [uri "/sftp-config.json"] [unique_id "178816460488.121535"] [ref ""], client: 170.101.96.53, server: ingelmart.com, request: "GET /sftp-config.json HTTP/1.1", host: "ingelmart.com"
2026/08/31 08:23:24 [error] 2115101#2115101: *112169 [client 170.101.96.53] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/loc
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-31 08:16:45
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:16:40.587072 2026] [security2:error] [pid 22780:tid 22780] [client 170.101.96.53:59133] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ingberinteriors.com"] [uri "/sftp-config.json"] [unique_id "apU4aPaUm47bIhjhRxx9TQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 07:48:06
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:48:01.637355 2026] [security2:error] [pid 21914:tid 21914] [client 170.101.96.53:49739] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infrared-heaters.us"] [uri "/sftp-config.json"] [unique_id "apUxscmpK5r3ULnT-aO40QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abuse-detection
2026-08-31 07:46:47
(11 hours ago)
Web security detection (http-sensitive-probe); path=/.vscode/sftp.json; status=301
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 06:44:58
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 02:44:53.261587 2026] [security2:error] [pid 2825:tid 2825] [client 170.101.96.53:62884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "informant-systems.com"] [uri "/sftp-config.json"] [unique_id "apUi5QJKPPcLSivUz7jjfwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-31 06:25:28
(13 hours ago)
[redacted] 170.101.96.53 - - [31/Aug/2026:07:25:26 +0100] "GET /[redacted] HTTP/1.1" 302 6768 0/4728 ...
show more
[redacted] 170.101.96.53 - - [31/Aug/2026:07:25:26 +0100] "GET /[redacted] HTTP/1.1" 302 6768 0/47281 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" [redacted] 170.101.96.53 - - [31/Aug/2026:07:25:27 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 6768 0/61190 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack