🇺🇸
TPI-Abuse
2026-09-09 04:55:06
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:55:01.419888 2026] [security2:error] [pid 693004:tid 693004] [client 2a09:bac5:46f3:18d2::279:49:54066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jacksonpropertyrentals.com"] [uri "/sftp-config.json"] [unique_id "aqDmpe1qhmnGD94xIHLheAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
SX Communications
2026-09-09 04:52:32
(12 hours ago)
Web vulnerability scanning / probing from 2a09:bac5:46f3:18d2::279:49: automated requests for CMS ad ...
show more
Web vulnerability scanning / probing from 2a09:bac5:46f3:18d2::279:49: automated requests for CMS admin paths, login endpoints, xmlrpc, and common scanner fingerprints over HTTPS. 2 hits; paths: /.vscode/sftp.json, /sftp-config.json.
show less
Port Scan
Hacking
Web App Attack
🇷🇴
clauss
2026-09-09 04:41:21
(12 hours ago)
2a09:bac5:46f3:18d2::279:49 - - [09/Sep/2026:07:41:19 +0300] "GET /.vscode/sftp.json HTTP/2.0" 301 0 ...
show more
2a09:bac5:46f3:18d2::279:49 - - [09/Sep/2026:07:41:19 +0300] "GET /.vscode/sftp.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
2a09:bac5:46f3:18d2::279:49 - - [09/Sep/2026:07:41:20 +0300] "GET /.vscode/sftp.json HTTP/2.0" 404 46954 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:15:27
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:15:23.601718 2026] [security2:error] [pid 17113:tid 17113] [client 2a09:bac5:46f3:18d2::279:49:34416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnmorogiello.com"] [uri "/sftp-config.json"] [unique_id "aqDdW5hcTh3VVdKjUvZjVwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 04:10:32
(13 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /sftp-config.json | 2026-09-09 04:10 UTC
show less
Hacking
Web App Attack
🇺🇸
Penny Packer
2026-09-09 02:40:07
(14 hours ago)
Fail2Ban apache-tripwires
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:42:54
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:42:47.774334 2026] [security2:error] [pid 21310:tid 21310] [client 2a09:bac5:46f3:18d2::279:49:26682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeremy-olson.com"] [uri "/sftp-config.json"] [unique_id "aqC5l5cklimCJpi6LYOa9AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:23:01
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:22:54.113014 2026] [security2:error] [pid 18617:tid 18617] [client 2a09:bac5:46f3:18d2::279:49:43326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lewpratt.com"] [uri "/sftp-config.json"] [unique_id "aqC07ga7hPuTegoeWTxHvwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:57:01
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:56:56.873347 2026] [security2:error] [pid 27064:tid 27064] [client 2a09:bac5:46f3:18d2::279:49:10934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inmosantanora.com"] [uri "/sftp-config.json"] [unique_id "aqCu2JTb4P6Pazg5wukt8wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:25:52
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:25:46.069967 2026] [security2:error] [pid 2406:tid 2406] [client 2a09:bac5:46f3:18d2::279:49:62524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jondamico.com"] [uri "/sftp-config.json"] [unique_id "aqCnisHdmkifZ2TbJ-tc_gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:05:48
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:05:43.855423 2026] [security2:error] [pid 26366:tid 26366] [client 2a09:bac5:46f3:18d2::279:49:58954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jewersmail.com"] [uri "/sftp-config.json"] [unique_id "aqCi1zpy2n4d3738Jkq6cwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 23:40:30
(17 hours ago)
146 requests with url.path *config.json
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 23:08:12
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:08:08.054228 2026] [security2:error] [pid 3237:tid 3237] [client 2a09:bac5:46f3:18d2::279:49:53288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gurusportz.com"] [uri "/sftp-config.json"] [unique_id "aqCVWIHodt5q9s18mB8cFAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:45:34
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:45:27.920741 2026] [security2:error] [pid 20463:tid 20463] [client 2a09:bac5:46f3:18d2::279:49:63032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gsrsv.org"] [uri "/sftp-config.json"] [unique_id "aqCQB2G916c3jRvbYO1OngAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:14:19
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:46f3:18d2::279:49 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:14:14.289125 2026] [security2:error] [pid 32617:tid 32617] [client 2a09:bac5:46f3:18d2::279:49:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "local639.com"] [uri "/sftp-config.json"] [unique_id "aqCItvh9X1euu3j8t7pHWwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack