🇺🇸
Penny Packer
2026-09-08 19:58:00
(3 days ago)
Fail2Ban apache-tripwires
Web App Attack
🇩🇪
4server
2026-09-08 19:37:17
(3 days ago)
[TueSep0821:37:11.1300782026][security2:error][pid2035476:tid2035563][client2a04:3543:1000:2310:ec66 ...
show more
[TueSep0821:37:11.1300782026][security2:error][pid2035476:tid2035563][client2a04:3543:1000:2310:ec66:afff:fe94:4ab2:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"spicydesign.ch\"][uri\"/sftp-config.json\"][unique_id\"aqBj5_xYvL6WaHznzwjWGQAAAMA\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:34:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-a ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-afff-fe94-4ab2.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:34:09.201081 2026] [security2:error] [pid 1747:tid 1747] [client 2a04:3543:1000:2310:ec66:afff:fe94:4ab2:56092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southernstatespool.com"] [uri "/sftp-config.json"] [unique_id "aqBjMa2BmwNbnaw045DsxQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:24:41
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-a ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-afff-fe94-4ab2.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:24:32.101010 2026] [security2:error] [pid 19666:tid 19666] [client 2a04:3543:1000:2310:ec66:afff:fe94:4ab2:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southernbroadcast.com"] [uri "/sftp-config.json"] [unique_id "aqAaoNQWZxCCSrEaQKjLywAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:55:25
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-a ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-afff-fe94-4ab2.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:55:21.440731 2026] [security2:error] [pid 19947:tid 19952] [client 2a04:3543:1000:2310:ec66:afff:fe94:4ab2:50272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sweeneyzone.com"] [uri "/sftp-config.json"] [unique_id "ap-jSUlndQTlJMa-vjxyiwAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-08 05:14:12
(4 days ago)
2 attacks on password/key grabbing URLs:
GET /.vscode/sftp.json HTTP/1.1
Hacking
🇺🇸
TPI-Abuse
2026-09-07 22:40:33
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-a ...
show more
(mod_security) mod_security (id:949110) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-afff-fe94-4ab2.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:40:29.858215 2026] [security2:error] [pid 12469:tid 12469] [client 2a04:3543:1000:2310:ec66:afff:fe94:4ab2:63577] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sunstrongmetal.com"] [uri "/sftp-config.json"] [unique_id "ap89XVg8422hOUyG8TGWCwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
strefapi_com
2026-09-07 16:30:45
(5 days ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-07 15:44:55
(5 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 15:00:38
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-a ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-afff-fe94-4ab2.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 11:00:30.651601 2026] [security2:error] [pid 10102:tid 10102] [client 2a04:3543:1000:2310:ec66:afff:fe94:4ab2:64522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tand.es"] [uri "/sftp-config.json"] [unique_id "ap7RjnOEfN3sTnc8WnhQCAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-07 14:49:09
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sweetpuddingtrap.online | URI: /sftp-config.json | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:31:00
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-a ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-afff-fe94-4ab2.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:30:54.106875 2026] [security2:error] [pid 13788:tid 13788] [client 2a04:3543:1000:2310:ec66:afff:fe94:4ab2:64416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taskmasterstech.com"] [uri "/sftp-config.json"] [unique_id "ap6SXn3bTbWUBXwT5p3WLQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:32:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-a ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-afff-fe94-4ab2.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:32:49.006724 2026] [security2:error] [pid 24341:tid 24341] [client 2a04:3543:1000:2310:ec66:afff:fe94:4ab2:63418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sweet16invitationsonline.com"] [uri "/sftp-config.json"] [unique_id "ap4-cU_4LgUfWIiqrtAqCwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:33:23
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-a ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-afff-fe94-4ab2.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:33:18.168337 2026] [security2:error] [pid 1157069:tid 1157069] [client 2a04:3543:1000:2310:ec66:afff:fe94:4ab2:55126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sublimetiles.com"] [uri "/sftp-config.json"] [unique_id "ap4wfvkflXTgsoFXuMxm-gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:01:21
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-a ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:3543:1000:2310:ec66:afff:fe94:4ab2 (ec66-afff-fe94-4ab2.v6.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:01:16.248261 2026] [security2:error] [pid 9147:tid 9147] [client 2a04:3543:1000:2310:ec66:afff:fe94:4ab2:60059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sundollsforever.org"] [uri "/sftp-config.json"] [unique_id "ap4M3NIE9XB8NLseZnSTTAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack