π¦πΊ
Bay13
2026-10-03 09:31:03
(12 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-03 06:46:52
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 217.216.91.225 (vmi3617737.contaboserver.net): ...
show more
(mod_security) mod_security (id:949110) triggered by 217.216.91.225 (vmi3617737.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 02:46:47.826357 2026] [security2:error] [pid 2494:tid 2494] [client 217.216.91.225:50756] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pleasejustfixit.org"] [uri "/sftp-config.json"] [unique_id "asCk1-mZ2hg_9cAkQ0szSwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-03 06:29:24
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.216.91.225 (vmi3617737.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.216.91.225 (vmi3617737.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 02:29:17.677963 2026] [security2:error] [pid 14138:tid 14138] [client 217.216.91.225:35948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "givemethemic.com"] [uri "/sftp-config.json"] [unique_id "asCgvXoOFkfb09x-zrDJqAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-03 06:11:33
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.216.91.225 (vmi3617737.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.216.91.225 (vmi3617737.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 02:11:26.422850 2026] [security2:error] [pid 27116:tid 27116] [client 217.216.91.225:54482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.3dcounty.com"] [uri "/"] [unique_id "asCcjtFDeZhRYR26Y79cqQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Vegascosmetics
2026-10-02 08:32:47
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local blo ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local block policy. Evidence: High Abuse + Suspicion (63, Abuse: 56)
show less
Hacking
Exploited Host
Web App Attack
π©πͺ
Reinhard
2026-10-02 07:43:48
(1 day ago)
Parameter or path manipulation, hacking. /.vscode/sftp.json
Hacking
π©πͺ
BlueWire Hosting
2026-10-02 05:16:45
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
π©πͺ
big-cloud.nl
2026-10-02 04:51:04
(1 day ago)
Try to access /.vscode/sftp.json
Web App Attack
π§πͺ
cmbplf
2026-10-02 04:26:55
(1 day ago)
153 requests with url.path *sftp.json
134 requests with url.path *config.json
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-01 12:30:00
(2 days ago)
(mod_security) mod_security (id:210580) triggered by 217.216.91.225 (vmi3617737.contaboserver.net): ...
show more
(mod_security) mod_security (id:210580) triggered by 217.216.91.225 (vmi3617737.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:29:55.561529 2026] [security2:error] [pid 9883:tid 9883] [client 217.216.91.225:39540] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "sftp-config.json" at REQUEST_COOKIES:handl_landing_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||cpking.com|F|2"] [data "Matched Data: sftp-config.json found within REQUEST_COOKIES:handl_landing_page: https:/selltojr.com/sftp-config.json"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "cpking.com"] [uri "/.vscode/sftp.json"] [unique_id "ar5SQ5nhDHRuoYFuA1TvCQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-10-01 07:01:46
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
π²π½
octageeks.com
2026-10-01 04:28:08
(2 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
π©πͺ
LRob
2026-10-01 03:25:29
(2 days ago)
Secret file probe | method: GET | path: /.vscode/sftp.json | ua: Mozilla/5.0 (Macintosh; Intel Mac O ...
show more
Secret file probe | method: GET | path: /.vscode/sftp.json | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Hacking
Web App Attack