๐บ๐ธ
TPI-Abuse
2026-09-25 04:15:11
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 00:15:07.755300 2026] [security2:error] [pid 11699:tid 11699] [client 213.163.193.12:50134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powerastronomy.com"] [uri "/sftp-config.json"] [unique_id "arX1S2OJDp0dx9WqEQJLhwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 01:27:07
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 21:27:00.102802 2026] [security2:error] [pid 24226:tid 24226] [client 213.163.193.12:61772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proyectando.com"] [uri "/sftp-config.json"] [unique_id "arXN5CxusoI8NevJVW2yTAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 22:41:03
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 18:40:57.757431 2026] [security2:error] [pid 20165:tid 20165] [client 213.163.193.12:49801] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stoneageartifacts.com"] [uri "/sftp-config.json"] [unique_id "arWm-SWL8haqkza4mBelHwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 21:06:57
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 17:06:50.949559 2026] [security2:error] [pid 22174:tid 22194] [client 213.163.193.12:60773] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "princesscastlebunkbed.com"] [uri "/sftp-config.json"] [unique_id "arWQ6hqM1KPVB_LZcxvsSAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 20:48:11
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 16:48:05.793510 2026] [security2:error] [pid 12303:tid 12303] [client 213.163.193.12:50202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "providentbusinessllc.com"] [uri "/sftp-config.json"] [unique_id "arWMhVkJOzwp372hEevZ-AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:47:09
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:47:03.250995 2026] [security2:error] [pid 30485:tid 30485] [client 213.163.193.12:63601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primestatepainting.com"] [uri "/sftp-config.json"] [unique_id "arVwJ1tOWZfFk2bbE2zQWQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-24 18:40:47
(12 hours ago)
Try to access /.vscode/sftp.json
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 16:40:00
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 12:39:56.264807 2026] [security2:error] [pid 816:tid 816] [client 213.163.193.12:53069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rohn.com"] [uri "/sftp-config.json"] [unique_id "arVSXORbyRHGmK5k28aPPQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 15:22:27
(15 hours ago)
(NGINX) Security rule triggered from 213.163.193.12 (SG/Singapore/213-163-193-12.sg-sin1.upcloud.hos ...
show more
(NGINX) Security rule triggered from 213.163.193.12 (SG/Singapore/213-163-193-12.sg-sin1.upcloud.host): 5 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 12:25:16
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 08:25:09.068841 2026] [security2:error] [pid 20796:tid 20796] [client 213.163.193.12:53557] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proventransmission.com"] [uri "/sftp-config.json"] [unique_id "arUWpXvvtbYZu8ZVTIiE5AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:52:53
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:52:45.971016 2026] [security2:error] [pid 13771:tid 13771] [client 213.163.193.12:52186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "primemanagementmn.com"] [uri "/sftp-config.json"] [unique_id "arTk3aPbXsPUFxRpMfbNCwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:57:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:57:19.023212 2026] [security2:error] [pid 8876:tid 8876] [client 213.163.193.12:63335] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "promoadvocate.com"] [uri "/sftp-config.json"] [unique_id "arS7v8bnb_WEWX1bTceHkAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-24 05:08:33
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฌ๐ง
consul.to
2026-09-24 04:35:31
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:03:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud. ...
show more
(mod_security) mod_security (id:210492) triggered by 213.163.193.12 (213-163-193-12.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:03:41.069334 2026] [security2:error] [pid 11384:tid 11384] [client 213.163.193.12:58252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "psychicangelreader.com"] [uri "/sftp-config.json"] [unique_id "arShHaqbRrs6tWfI9lfvCQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack