๐บ๐ธ
TPI-Abuse
2026-06-26 07:53:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 03:53:02.445488 2026] [security2:error] [pid 22632:tid 22632] [client 188.241.126.11:6028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acsellsre.com"] [uri "/sftp-config.json"] [unique_id "aj4v3oidRa_R-SrAm11HPwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-26 04:24:43
(4 hours ago)
Try to access /.vscode/sftp.json
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 04:07:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 00:07:22.705054 2026] [security2:error] [pid 27573:tid 27573] [client 188.241.126.11:3778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achildsspace2.com"] [uri "/sftp-config.json"] [unique_id "aj36-thihXtjNNbkyC4r_QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 01:02:56
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 21:02:51.787271 2026] [security2:error] [pid 22592:tid 22597] [client 188.241.126.11:22046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accreditedfinancialanalyst.com"] [uri "/sftp-config.json"] [unique_id "aj3Pu60RBoXWb4VycDlpkQAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-25 09:12:17
(23 hours ago)
[ThuJun2511:12:13.7936402026][security2:error][pid2819558:tid2819713][client188.241.126.11:0]ModSecu ...
show more
[ThuJun2511:12:13.7936402026][security2:error][pid2819558:tid2819713][client188.241.126.11:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mm-ingegneria.ch\"][uri\"/sftp-config.json\"][unique_id\"ajzw7RanNTE_kTcnuE3RpQAAAQw\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 04:53:08
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210580) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 00:53:00.520928 2026] [security2:error] [pid 28833:tid 28833] [client 188.241.126.11:52368] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "sftp-config.json" at REQUEST_COOKIES:handl_landing_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||mkdesignndetailing.com|F|2"] [data "Matched Data: sftp-config.json found within REQUEST_COOKIES:handl_landing_page: https:/miraaustin.com/sftp-config.json"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "mkdesignndetailing.com"] [uri "/.vscode/sftp.json"] [unique_id "ajy0LAPiJDtlHPNi5C0usAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 02:12:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 22:12:43.292457 2026] [security2:error] [pid 24254:tid 24254] [client 188.241.126.11:57860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "miz-art.com"] [uri "/sftp-config.json"] [unique_id "ajyOmyRw7jO7FvjM9w1yVAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 01:51:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 21:51:03.263614 2026] [security2:error] [pid 5521:tid 5521] [client 188.241.126.11:17018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "miyabi-classicalacupuncture.com"] [uri "/sftp-config.json"] [unique_id "ajyJh132vbMr5-o8CqtHhgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 01:32:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 21:32:37.965441 2026] [security2:error] [pid 20217:tid 20217] [client 188.241.126.11:12512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mixmediallc.com"] [uri "/sftp-config.json"] [unique_id "ajyFNerVgGWmev8XcYgJKQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 20:10:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 16:10:40.183814 2026] [security2:error] [pid 614:tid 614] [client 188.241.126.11:39546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "misogynyis.com"] [uri "/sftp-config.json"] [unique_id "ajw5wGCKqzcuEQWhzdTQLAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-24 18:45:18
(1 day ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฉ๐ช
4server
2026-06-24 16:36:37
(1 day ago)
[WedJun2418:36:32.6745992026][security2:error][pid354745:tid354796][client188.241.126.11:0]ModSecuri ...
show more
[WedJun2418:36:32.6745992026][security2:error][pid354745:tid354796][client188.241.126.11:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"miotrentino.it\"][uri\"/sftp-config.json\"][unique_id\"ajwHkMUBBbL9_ioTGciREgAAAMY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
MM-bot
2026-06-24 07:55:40
(2 days ago)
URL-probe: HTTP/1.1 GET request on /sftp-config.json (2026-06-24 09:55:40 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-24 06:21:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 02:21:00.147916 2026] [security2:error] [pid 6392:tid 6392] [client 188.241.126.11:10720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "militaryordnance.com"] [uri "/sftp-config.json"] [unique_id "ajt3TCxt3Dk3jwF_Gz--cwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 22:42:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.241.126.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 18:42:43.562156 2026] [security2:error] [pid 4453:tid 4453] [client 188.241.126.11:25884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "midcityrotary.org"] [uri "/sftp-config.json"] [unique_id "ajsL44T0JVMxjhkA3Cm8bwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack