๐บ๐ธ
mnsf
2026-09-01 20:05:18
(1 hour ago)
Too many Status 40X (13)
Request Overload (290)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 17:19:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 13:19:31.684081 2026] [security2:error] [pid 20480:tid 20480] [client 170.101.96.67:58441] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pluscures.com"] [uri "/sftp-config.json"] [unique_id "apcJI8SR9PnmSxmTuk2nZAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:07:26
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:07:18.148071 2026] [security2:error] [pid 25960:tid 25960] [client 170.101.96.67:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hondabvi.com"] [uri "/sftp-config.json"] [unique_id "apax5nQ94b1Q3j_bG_mUkQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-01 08:36:23
(12 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: \.vscode (Match: .vscode)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:02:34
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:02:23.204423 2026] [security2:error] [pid 13124:tid 13124] [client 170.101.96.67:55267] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adults-biz.com"] [uri "/sftp-config.json"] [unique_id "apZqbwpXK8kS1Cqf_AfWhQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-01 05:13:59
(16 hours ago)
2 attacks on password grabbing URLs:
GET /.vscode/sftp.json HTTP/1.1
Hacking
๐ซ๐ท
Baking333
2026-09-01 04:48:25
(16 hours ago)
[redacted] 170.101.96.67 - - [01/Sep/2026:05:48:23 +0100] "GET /[redacted] HTTP/1.1" 302 6843 0/7447 ...
show more
[redacted] 170.101.96.67 - - [01/Sep/2026:05:48:23 +0100] "GET /[redacted] HTTP/1.1" 302 6843 0/74479 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" [redacted] 170.101.96.67 - - [01/Sep/2026:05:48:23 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 6848 0/163782 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:44:02
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:43:52.971276 2026] [security2:error] [pid 22979:tid 22979] [client 170.101.96.67:65319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerryhetrick.com"] [uri "/sftp-config.json"] [unique_id "apZYCAHaxzpXXzaQxLypQAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 03:58:24
(17 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-01 03:42:54
(17 hours ago)
Automatically blocked due to distributed attack
Hacking
๐ฉ๐ช
R.G.
2026-09-01 03:11:03
(18 hours ago)
(CT) IP 170.101.96.67 (US/United States/-) found to have 214 connections; Ports: *; Direction: inout ...
show more
(CT) IP 170.101.96.67 (US/United States/-) found to have 214 connections; Ports: *; Direction: inout; Trigger: CT_LIMIT; Logs:
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:00:16
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:00:09.894570 2026] [security2:error] [pid 2158:tid 2158] [client 170.101.96.67:54624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cultureal.com"] [uri "/sftp-config.json"] [unique_id "apY_ubX1qNUje-BxSIgDsAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
omc
2026-09-01 02:45:32
(18 hours ago)
Hacking login/admin service [Q3].
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 01:31:16
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:31:11.533104 2026] [security2:error] [pid 1752:tid 1752] [client 170.101.96.67:61527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dojaservices.com"] [uri "/sftp-config.json"] [unique_id "apYq38YJuHvgDFM8Fa4eygAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:54:20
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.101.96.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:54:11.429407 2026] [security2:error] [pid 9804:tid 9804] [client 170.101.96.67:49955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "golf-4-good.com"] [uri "/sftp-config.json"] [unique_id "apYiM_40XPMhXxdvylKCJwAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack