๐บ๐ธ
TPI-Abuse
2026-08-31 22:23:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:23:13.902780 2026] [security2:error] [pid 4507:tid 4507] [client 27.109.115.128:5074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wavecomputers.com"] [uri "/sftp-config.json"] [unique_id "apX-0WPsrlX-kORum0nNEwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 21:55:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 17:55:31.848981 2026] [security2:error] [pid 30037:tid 30037] [client 27.109.115.128:36613] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisdomwfm.com"] [uri "/sftp-config.json"] [unique_id "apX4UzQ0N8EPIpeZ3RfUngAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 21:04:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 17:04:10.907809 2026] [security2:error] [pid 23883:tid 23883] [client 27.109.115.128:27533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "westonimports.com"] [uri "/sftp-config.json"] [unique_id "apXsSlQvIWs8jNvCTjfU4AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 20:47:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 16:47:47.022083 2026] [security2:error] [pid 28978:tid 28978] [client 27.109.115.128:13285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whatcausesmentalillness.com"] [uri "/sftp-config.json"] [unique_id "apXoczgDkQkvPWY-nX_C0gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 20:29:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 16:29:20.603807 2026] [security2:error] [pid 29839:tid 29839] [client 27.109.115.128:57243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wgs.cc"] [uri "/sftp-config.json"] [unique_id "apXkIEqbMnBHhE7O_HVINwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 20:14:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 16:13:58.527344 2026] [security2:error] [pid 30682:tid 30682] [client 27.109.115.128:19444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wasabioldies.com"] [uri "/sftp-config.json"] [unique_id "apXghnUjI_jK1DazMMtj_gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 19:50:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 27.109.115.128 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 15:50:36.725850 2026] [security2:error] [pid 11727:tid 11772] [client 27.109.115.128:28015] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "woadwellness.com"] [uri "/sftp-config.json"] [unique_id "apXbDBmpWh5f8CZfUynMJAAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-08-05 08:02:40
(4 weeks ago)
tcp/23
Port Scan
๐บ๐ธ
kosada.com
2026-08-01 10:15:23
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
drewf.ink
2026-07-28 13:32:45
(1 month ago)
[13:32] Triggered SMB honeypot. Type: NetBIOS + SMB1. Dialect(s): LANMAN1.0, LM1.2X002, NT LANMAN 1. ...
show more
[13:32] Triggered SMB honeypot. Type: NetBIOS + SMB1. Dialect(s): LANMAN1.0, LM1.2X002, NT LANMAN 1.0, NT LM 0.12
show less
Hacking
Exploited Host
๐ซ๐ท
sthoyer.de
2026-07-28 12:53:48
(1 month ago)
Jul 28 14:53:47 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f ...
show more
Jul 28 14:53:47 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=27.109.115.128 DST=173.212.223.67 LEN=52 TOS=0x00 PREC=0x00 TTL=110 ID=3089 DF PROTO=TCP SPT=23455 DPT=445 WINDOW=8192 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ฉ๐ช
check-the-sum.fr
2026-07-27 05:31:52
(1 month ago)
Port Scanning
Port Scan
๐บ๐ธ
kosada.com
2026-07-11 20:36:26
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2026-06-29 07:01:09
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-02-22 00:18:11
(6 months ago)
DDoS botnet 510.000+ IPs; URL with bing/trustpilot/githubhelp and %C2%A4 or \xc2\xa4. NEW 09/2025: a ...
show more
DDoS botnet 510.000+ IPs; URL with bing/trustpilot/githubhelp and %C2%A4 or \xc2\xa4. NEW 09/2025: amplification attacks via third-parties e.g. HTTP_USER_AGENT facebookexternalhit/meta-externalagent/meta-externalfetcher or IPs from googleusercontent.com with fake HTTP_REFERER foxnews.com/newsweek.com/upwork.com/activision.com/... Port 443.
show less
DDoS Attack
Bad Web Bot
Web App Attack