π©πͺ
Vegascosmetics
2025-10-19 21:51:09
(11 months ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
π³π±
homeshowdomain.nl
2025-10-18 22:01:47
(11 months ago)
Auto-ban: >3000 req/min op 2025-10-18
Hacking
Web App Attack
SSH
π©πͺ
conseilgouz
2025-10-18 17:06:10
(11 months ago)
ece-22 : 8G : REQUEST_URI error=>/sftp-config.json
Hacking
πΊπΈ
TPI-Abuse
2025-10-18 16:29:12
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 174.138.27.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 174.138.27.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 18 12:29:07.896509 2025] [security2:error] [pid 344:tid 344] [client 174.138.27.63:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eddysgroup.com"] [uri "/sftp-config.json"] [unique_id "aPPAUx6Tk4z0BssYHI5a0wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
MarkGGN
2025-10-18 15:13:19
(11 months ago)
Webexploits. 174.138.27.63 - - [18/Oct/2025:17:13:09 +0200] "GET /sftp-config.json HTTP/1.1" 301 162 ...
show more
Webexploits. 174.138.27.63 - - [18/Oct/2025:17:13:09 +0200] "GET /sftp-config.json HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
174.138.27.63 - - [18/Oct/2025:17:13:18 +0200] "GET /.vscode/sftp.json HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-18 14:40:10
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 174.138.27.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 174.138.27.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 18 10:40:06.464926 2025] [security2:error] [pid 31926:tid 31926] [client 174.138.27.63:49174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "landeagle.com"] [uri "/sftp-config.json"] [unique_id "aPOmxu2iljv5eGnuXbDf4wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-18 13:55:37
(11 months ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /sftp-config.json
Web App Attack
πΊπΈ
Penny Packer
2025-10-18 12:23:12
(11 months ago)
Fail2Ban apache-tripwires
Web App Attack
Anonymous
2025-10-18 09:49:03
(11 months ago)
(mod_security) mod_security triggered on hostname [redacted] 174.138.27.63 (SG/Singapore/-)
SQL Injection
Anonymous
2025-10-18 09:44:05
(11 months ago)
Infected user bad webscan
Exploited Host
π«π·
conseilgouz
2025-10-18 07:10:52
(11 months ago)
sae-22 : 8G : REQUEST_URI error=>/sftp-config.json
Hacking
πΊπΈ
TPI-Abuse
2025-10-18 06:44:51
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 174.138.27.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 174.138.27.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 18 02:44:45.784546 2025] [security2:error] [pid 1808:tid 1808] [client 174.138.27.63:61611] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shivermedia.com"] [uri "/sftp-config.json"] [unique_id "aPM3XSBVvPOex218TVqoEAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
kosada.com
2025-10-18 05:34:07
(11 months ago)
Web vulnerability probing: /sftp-config.json
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-18 03:09:33
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 174.138.27.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 174.138.27.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 17 23:09:25.732027 2025] [security2:error] [pid 8138:tid 8138] [client 174.138.27.63:63531] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vanmetermailing.com"] [uri "/sftp-config.json"] [unique_id "aPME5cfy3Xn21YHY0jXGdAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
nzhost.co.nz
2025-10-18 02:33:32
(11 months ago)
$f2bV_matches
Hacking
Brute-Force