๐บ๐ธ
TPI-Abuse
2026-08-28 19:05:43
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:05:38.032730 2026] [security2:error] [pid 8443:tid 8443] [client 185.55.243.172:51140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goseethenurse.com"] [uri "/sftp-config.json"] [unique_id "apHcAltRamP0yGdAD3VeRgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-28 18:56:42
(7 hours ago)
[28/Aug/2026:21:56:42 +0300] -- 185.55.243.172 Ban reason: User-Agent python-requests
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 18:55:56
(7 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /sftp-config.json (+1 more) | 2026-08-28 18:55 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:46:29
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:46:25.982761 2026] [security2:error] [pid 21478:tid 21478] [client 185.55.243.172:60691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.al-ketab.net"] [uri "/sftp-config.json"] [unique_id "apHXgfHj6ttQSRs87245MgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
VXG-NET
2026-08-28 18:42:10
(8 hours ago)
port=80, indicator_type=info-leak
Hacking
๐ซ๐ฎ
paissangroup
2026-08-28 18:23:29
(8 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:19:06
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:19:02.301026 2026] [security2:error] [pid 17102:tid 17102] [client 185.55.243.172:62904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.limobuswichita.com"] [uri "/sftp-config.json"] [unique_id "apHRFkdnPXkOGIoss_fEIAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-08-28 18:11:34
(8 hours ago)
[PROTECTED PATHS] crawler credentials.ini, aws.ini, aws.yml, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:02:09
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:02:02.469851 2026] [security2:error] [pid 3912:tid 3912] [client 185.55.243.172:53413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.monteriggioni.net"] [uri "/sftp-config.json"] [unique_id "apHNGsNyK9PXX726ei8lhAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-28 17:59:52
(8 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:46:43
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:46:39.266451 2026] [security2:error] [pid 25550:tid 25550] [client 185.55.243.172:56725] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jtagulator.com"] [uri "/sftp-config.json"] [unique_id "apHJf6EJkGVdJgGtAdz5GgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-28 17:44:45
(8 hours ago)
[FriAug2819:44:40.9376222026][security2:error][pid2366732:tid2367224][client185.55.243.172:0]ModSecu ...
show more
[FriAug2819:44:40.9376222026][security2:error][pid2366732:tid2367224][client185.55.243.172:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"python-requests/\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"203\"][id\"332039\"][rev\"4\"][msg\"Atomicorp.comWAFRules:SuspiciousUnusualUserAgent\(python-requests\).Disablethisruleifyouusepython-requests/.\"][severity\"CRITICAL\"][hostname\"www.shakary.com\"][uri\"/sftp-config.json\"][unique_id\"apHJCKk--RQ8hawiUxjtTgAAARQ\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:30:07
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:30:02.451995 2026] [security2:error] [pid 9888:tid 9888] [client 185.55.243.172:57765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killarneypool.org"] [uri "/sftp-config.json"] [unique_id "apHFmn_0yNg__8OtR2_W0wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:52:36
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 185.55.243.172 (kl15.topdealnl.us): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:52:27.911997 2026] [security2:error] [pid 22556:tid 22556] [client 185.55.243.172:59644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.indie100.com"] [uri "/sftp-config.json"] [unique_id "apG8y5xhhyEOlNegNGa9FAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Duggy_Tuxy๐งฑ
2026-06-23 05:06:08
(2 months ago)
[HP02-SRV02-FR] Blocked by SysWarden Firewall (Port Scan / Probing)
Port Scan