Anonymous
2026-08-25 00:15:30
(34 minutes ago)
Bad Web Bot
π«π·
Baking333
2026-08-24 23:18:04
(1 hour ago)
[redacted] 170.101.96.54 - - [25/Aug/2026:00:18:02 +0100] "GET /[redacted] HTTP/1.1" 302 6868 0/1365 ...
show more
[redacted] 170.101.96.54 - - [25/Aug/2026:00:18:02 +0100] "GET /[redacted] HTTP/1.1" 302 6868 0/136590 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" [redacted] 170.101.96.54 - - [25/Aug/2026:00:18:02 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 6873 0/73513 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
π·π΄
clauss
2026-08-24 22:34:43
(2 hours ago)
170.101.96.54 - - [25/Aug/2026:01:34:40 +0300] "GET /.vscode/sftp.json HTTP/2.0" 301 0 "-" "Mozilla/ ...
show more
170.101.96.54 - - [25/Aug/2026:01:34:40 +0300] "GET /.vscode/sftp.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
170.101.96.54 - - [25/Aug/2026:01:34:42 +0300] "GET /.vscode/sftp.json HTTP/2.0" 404 24889 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
...
show less
Web App Attack
π«π·
Baking333
2026-08-24 20:33:05
(4 hours ago)
[redacted] 170.101.96.54 - - [24/Aug/2026:21:33:03 +0100] "GET /[redacted] HTTP/1.1" 302 6843 0/3268 ...
show more
[redacted] 170.101.96.54 - - [24/Aug/2026:21:33:03 +0100] "GET /[redacted] HTTP/1.1" 302 6843 0/32688 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" [redacted] 170.101.96.54 - - [24/Aug/2026:21:33:03 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 6848 0/31807 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
π«π·
Baking333
2026-08-24 16:32:13
(8 hours ago)
[redacted] 170.101.96.54 - - [24/Aug/2026:17:32:11 +0100] "GET /[redacted] HTTP/1.1" 302 6858 0/5128 ...
show more
[redacted] 170.101.96.54 - - [24/Aug/2026:17:32:11 +0100] "GET /[redacted] HTTP/1.1" 302 6858 0/51285 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" [redacted] 170.101.96.54 - - [24/Aug/2026:17:32:11 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 6863 0/53650 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-08-24 13:13:33
(11 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-08-24 12:45:27
(12 hours ago)
GET sftp-config.json | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like ...
show more
GET sftp-config.json | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 | Time: 2026-08-24 12:45:27 UTC
show less
Web App Attack
Anonymous
2026-08-24 12:21:22
(12 hours ago)
Bot / seems abusive / Apache connections: 69
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
π΅π±
sefinek.net
2026-08-24 07:55:33
(16 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /sftp-config.json | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 β’ Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π²π½
octageeks.com
2026-08-24 04:15:43
(20 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 04:12:58
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:12:51.827117 2026] [security2:error] [pid 26015:tid 26015] [client 170.101.96.54:50900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tech-servusa.com"] [uri "/sftp-config.json"] [unique_id "aovEw9-VtyekxIQflTMalAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 01:45:41
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 21:45:34.563496 2026] [security2:error] [pid 6324:tid 6324] [client 170.101.96.54:60964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teamconnell.com"] [uri "/sftp-config.json"] [unique_id "aouiPoR31OpxZBxVmaQrpgAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Vegascosmetics
2026-08-24 01:18:08
(23 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: \.vscode (Match: .vscode)
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 23:55:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 19:55:20.691143 2026] [security2:error] [pid 16510:tid 16510] [client 170.101.96.54:64309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tdsdemo.com"] [uri "/sftp-config.json"] [unique_id "aouIaK0MDowSCAxHfTpOhAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
ambor
2026-08-23 22:38:55
(1 day ago)
Honeypot triggered on tcpdata.com - Attempted to access /sftp-config.json (config_file_probe). User- ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /sftp-config.json (config_file_probe). User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36
show less
Web App Attack