๐บ๐ธ
TPI-Abuse
2026-06-17 04:04:58
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 00:04:52.329773 2026] [security2:error] [pid 8501:tid 8501] [client 188.214.199.12:16398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mdgcontrols.com"] [uri "/sftp-config.json"] [unique_id "ajIc5MsDFFUqn8_89W8kIwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-06-16 19:13:22
(6 days ago)
[redacted] 188.214.199.12 - - [16/Jun/2026:20:13:19 +0100] "GET /[redacted] HTTP/1.1" 302 5363 0/124 ...
show more
[redacted] 188.214.199.12 - - [16/Jun/2026:20:13:19 +0100] "GET /[redacted] HTTP/1.1" 302 5363 0/124193 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" [redacted] 188.214.199.12 - - [16/Jun/2026:20:13:20 +0100] "GET /[redacted] HTTP/1.1" 302 5278 0/322663 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 16:51:33
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 12:51:28.235062 2026] [security2:error] [pid 23819:tid 23819] [client 188.214.199.12:20200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mavrik12.com"] [uri "/sftp-config.json"] [unique_id "ajF_ENnZIF5SB7CTRsOKLgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 15:53:50
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 11:53:43.507114 2026] [security2:error] [pid 31448:tid 31448] [client 188.214.199.12:12626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maunakeavista.com"] [uri "/sftp-config.json"] [unique_id "ajFxh5cdGFkgbKM9dumwTQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-06-16 12:42:13
(1 week ago)
Scanning for exploits - /.vscode/sftp.json
Web App Attack
๐ฉ๐ช
4server
2026-06-14 21:30:32
(1 week ago)
[SunJun1423:30:29.2815332026][security2:error][pid2397640:tid2397731][client188.214.199.12:0]ModSecu ...
show more
[SunJun1423:30:29.2815332026][security2:error][pid2397640:tid2397731][client188.214.199.12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"gualandi.ch\"][uri\"/sftp-config.json\"][unique_id\"ai8ddRdi3Jy3jZW4V59LLAAAAJg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 16:48:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 12:48:36.140891 2026] [security2:error] [pid 20917:tid 20917] [client 188.214.199.12:34792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gsrsv.org"] [uri "/sftp-config.json"] [unique_id "ai7bZAhpOBTmUmSB6YMYOgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 10:44:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:44:09.373813 2026] [security2:error] [pid 6624:tid 6624] [client 188.214.199.12:44846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grupogasa.com"] [uri "/sftp-config.json"] [unique_id "ai6F-TIJ_m-FJ8xIoFyKWwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-13 17:45:10
(1 week ago)
[SatJun1319:45:06.1401852026][security2:error][pid1461221:tid1461239][client188.214.199.12:0]ModSecu ...
show more
[SatJun1319:45:06.1401852026][security2:error][pid1461221:tid1461239][client188.214.199.12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"grigorov.ch\"][uri\"/sftp-config.json\"][unique_id\"ai2XIsY_eSwv4Hce4RjBFgAAAAU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 14:13:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 10:12:56.743422 2026] [security2:error] [pid 21612:tid 21612] [client 188.214.199.12:38962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gregquinn.com"] [uri "/sftp-config.json"] [unique_id "ai1laMUVAzf3zSWR_QgWrAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 05:00:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 01:00:49.641559 2026] [security2:error] [pid 7404:tid 7404] [client 188.214.199.12:26590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greatwesternfirearms.com"] [uri "/sftp-config.json"] [unique_id "aizkARr4mwt3b5lCDgsA4wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 00:06:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 20:06:47.826673 2026] [security2:error] [pid 11845:tid 11845] [client 188.214.199.12:10056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grasslakepizzatime.com"] [uri "/sftp-config.json"] [unique_id "aiyfF8nlDxgxHFoIeAbPSgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 20:42:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 16:41:57.234102 2026] [security2:error] [pid 8816:tid 8816] [client 188.214.199.12:43122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "butterflymornings.com"] [uri "/sftp-config.json"] [unique_id "aixvFeZyZIY8_4SKT3BHXQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 15:53:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.214.199.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 11:52:59.902454 2026] [security2:error] [pid 18274:tid 18274] [client 188.214.199.12:62746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gracebaptisthartsville.com"] [uri "/sftp-config.json"] [unique_id "aiwrWyUUGN7e37r6RhDT_wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-12 15:13:17
(1 week ago)
Try to access /.vscode/sftp.json
Web App Attack