🇺🇸
TPI-Abuse
2026-09-06 03:51:31
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:23.245562 2026] [security2:error] [pid 1234:tid 1234] [client 2a09:bac5:46f2:18d2::279:85:27260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "exhaustthelimits.org"] [uri "/sftp-config.json"] [unique_id "apzjO6FhFoATULtVfatflQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:02:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:02:05.179187 2026] [security2:error] [pid 19074:tid 19074] [client 2a09:bac5:46f2:18d2::279:85:17940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "expresstires.us"] [uri "/sftp-config.json"] [unique_id "apzXrdZdY1cHN4Xoitj_nAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:46:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:45:55.594823 2026] [security2:error] [pid 27889:tid 27889] [client 2a09:bac5:46f2:18d2::279:85:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ruralcommunitycare.org"] [uri "/sftp-config.json"] [unique_id "apzT4xDLMV1PXT_-7oR5hgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:12:39
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:12:35.087289 2026] [security2:error] [pid 17465:tid 17465] [client 2a09:bac5:46f2:18d2::279:85:51980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kruizekontrhl.com"] [uri "/sftp-config.json"] [unique_id "apzME1imuOFOyuXQm9fTmAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
eryilmaz
2026-09-06 02:00:30
(2 hours ago)
Automated attack blocked by eryilmaz WAF/fail2ban: 1 event(s) [waf.block] in the last 1 days, e.g. / ...
show more
Automated attack blocked by eryilmaz WAF/fail2ban: 1 event(s) [waf.block] in the last 1 days, e.g. /sftp-config.json
show less
Web App Attack
Hacking
🇩🇪
LRob
2026-09-05 23:48:11
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /sftp-config.json | 2026-09-05 23:48 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:26:32
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:26:23.260554 2026] [security2:error] [pid 11136:tid 11136] [client 2a09:bac5:46f2:18d2::279:85:17760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eta-mct.com"] [uri "/sftp-config.json"] [unique_id "apyXDykiVFIavTrESoFcYwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:59:32
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:59:26.469286 2026] [security2:error] [pid 26641:tid 26641] [client 2a09:bac5:46f2:18d2::279:85:49344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ergocorrect.com"] [uri "/sftp-config.json"] [unique_id "apyCrqpU9c-GxCc59umGKQAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:31:45
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:31:38.932909 2026] [security2:error] [pid 8652:tid 8652] [client 2a09:bac5:46f2:18d2::279:85:21520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kawkacevents.com"] [uri "/sftp-config.json"] [unique_id "apx8KhGZfSduo5K7eZnGXAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-05 20:31:31
(7 hours ago)
206 requests with url.path *config.json
151 requests with url.path *sftp.json
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-05 18:45:38
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f2:18d2::279:85 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 14:45:31.956669 2026] [security2:error] [pid 3102469:tid 3102469] [client 2a09:bac5:46f2:18d2::279:85:49842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "engineeringarts.com"] [uri "/sftp-config.json"] [unique_id "apxjS7O_v6otSpTO5tI-JgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-05 18:32:57
(9 hours ago)
2a09:bac5:46f2:18d2::279:85 - - [05/Sep/2026:21:32:54 +0300] "GET /.vscode/sftp.json HTTP/2.0" 301 0 ...
show more
2a09:bac5:46f2:18d2::279:85 - - [05/Sep/2026:21:32:54 +0300] "GET /.vscode/sftp.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
2a09:bac5:46f2:18d2::279:85 - - [05/Sep/2026:21:32:57 +0300] "GET /.vscode/sftp.json HTTP/2.0" 404 11134 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack