๐ฉ๐ช
XICTRON
2026-09-27 12:15:07
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 07:05:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2605:a140:2358:423::1 (vmi3580423.contaboserver ...
show more
(mod_security) mod_security (id:210492) triggered by 2605:a140:2358:423::1 (vmi3580423.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 03:05:28.782129 2026] [security2:error] [pid 29547:tid 29584] [client 2605:a140:2358:423::1:53794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darrylrichards.com"] [uri "/sftp-config.json"] [unique_id "arjAOIdr2bSYdl0sJPn4ZgAAAYU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-27 05:48:55
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-09-26 20:57:58
(1 day ago)
$f2bV_matches
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-25 22:54:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2605:a140:2358:423::1 (vmi3580423.contaboserver ...
show more
(mod_security) mod_security (id:210492) triggered by 2605:a140:2358:423::1 (vmi3580423.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 18:54:19.720473 2026] [security2:error] [pid 10718:tid 10718] [client 2605:a140:2358:423::1:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "easy-byte.net"] [uri "/sftp-config.json"] [unique_id "arb7mx2mszSJ4Vpvn5f-cQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 17:10:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2605:a140:2358:423::1 (vmi3580423.contaboserver ...
show more
(mod_security) mod_security (id:210492) triggered by 2605:a140:2358:423::1 (vmi3580423.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 13:10:10.739163 2026] [security2:error] [pid 11423:tid 11423] [client 2605:a140:2358:423::1:55648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radtraininginc.com"] [uri "/sftp-config.json"] [unique_id "araq8mLH7WEXBd9ogsVVZwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 05:31:33
(3 days ago)
2605:a140:2358:423::1 - - [25/Sep/2026:05:31:32 +0000] "GET /.vscode/sftp.json HTTP/2.0" 404 1005 " ...
show more
2605:a140:2358:423::1 - - [25/Sep/2026:05:31:32 +0000] "GET /.vscode/sftp.json HTTP/2.0" 404 1005 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" "2605:a140:2358:423::1" "-"
...
show less
Web App Attack
๐บ๐ธ
nyt
2026-09-24 05:50:08
(4 days ago)
Deploy Config Probe
Web App Attack
๐ง๐ช
cmbplf
2026-09-23 08:07:01
(5 days ago)
130 requests with url.path *config.json
Brute-Force
Bad Web Bot
๐ฌ๐ง
pinguin
2026-09-21 22:46:01
(6 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /sftp-config.json
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
shadowgaming
2026-09-21 09:13:50
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /sftp-config.json | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-09-18 03:37:30
(1 week ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ซ๐ท
Baking333
2026-09-18 00:34:15
(1 week ago)
[redacted] 2605:a140:2358:423::1 - - [18/Sep/2026:01:34:13 +0100] "GET /[redacted] HTTP/1.1" 302 686 ...
show more
[redacted] 2605:a140:2358:423::1 - - [18/Sep/2026:01:34:13 +0100] "GET /[redacted] HTTP/1.1" 302 6868 0/48119 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" 443 [redacted] 2605:a140:2358:423::1 - - [18/Sep/2026:01:34:13 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 6873 0/50731 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" 443
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-09-16 19:27:10
(1 week ago)
[redacted] 2605:a140:2358:423::1 - - [16/Sep/2026:20:27:09 +0100] "GET /.vscode/[redacted] HTTP/1.1" ...
show more
[redacted] 2605:a140:2358:423::1 - - [16/Sep/2026:20:27:09 +0100] "GET /.vscode/[redacted] HTTP/1.1" 302 6863 0/51773 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" 443 [redacted] 2605:a140:2358:423::1 - - [16/Sep/2026:20:27:09 +0100] "GET /[redacted] HTTP/1.1" 302 6858 0/58301 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" 443
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 12:15:13
(1 week ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /sftp-config.json | 2026-09-16 12:15 UTC
show less
Hacking
Web App Attack