๐ฆ๐บ
nktnet
2025-05-18 22:42:00
(1 year ago)
requesting /.vscode endpoints
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2025-05-09 05:13:56
(1 year ago)
11 attacks on password grabbing URLs:
GET /.vscode/sftp.json HTTP/1.1
Hacking
๐ฉ๐ช
FeG Deutschland
2025-05-09 04:19:25
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2025-05-08 22:30:00
(1 year ago)
Multiple unauthorized attempt to access to non-existent path
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-08 22:17:39
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 52.47.125.32 (ec2-52-47-125-32.eu-west-3.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.47.125.32 (ec2-52-47-125-32.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 08 18:17:33.386429 2025] [security2:error] [pid 2387913:tid 2387913] [client 52.47.125.32:62101] [client 52.47.125.32] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fastr-wellington.com"] [uri "/sftp-config.json"] [unique_id "aB0tfWlxsi-dexvYEJKfGgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2025-05-08 22:17:00
(1 year ago)
Web vulnerability probing
Web App Attack
๐ฉ๐ช
Mr-Money
2025-05-08 22:13:06
(1 year ago)
05/Mar/2025:19:52:10 +010052.47.125.32 - - [09/May/2025:00:13:06 +0200] "GET /.vscode/sftp.json HTTP ...
show more
05/Mar/2025:19:52:10 +010052.47.125.32 - - [09/May/2025:00:13:06 +0200] "GET /.vscode/sftp.json HTTP/1.1" 404 497 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-08 22:01:23
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 52.47.125.32 (ec2-52-47-125-32.eu-west-3.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.47.125.32 (ec2-52-47-125-32.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 08 18:01:20.132090 2025] [security2:error] [pid 4025093:tid 4025093] [client 52.47.125.32:56522] [client 52.47.125.32] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feelgood70s.xs80s.com"] [uri "/sftp-config.json"] [unique_id "aB0psMZEpOiNaUHO6CUSsgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
rakkor
2025-05-08 21:46:27
(1 year ago)
2025/05/08 22:46:26 [error] 28005#28005: *6857954 open() "/var/services/web/sftp-config.json" failed ...
show more
2025/05/08 22:46:26 [error] 28005#28005: *6857954 open() "/var/services/web/sftp-config.json" failed (2: No such file or directory), client: 52.47.125.32, server: , request: "GET /sftp-config.json HTTP/1.1", host: "filebrowser.rakkor.uk"
2025/05/08 22:46:26 [error] 28004#28004: *6857957 open() "/var/services/web/.vscode/sftp.json" failed (2: No such file or directory), client: 52.47.125.32, server: , request: "GET /.vscode/sftp.json HTTP/1.1", host: "filebrowser.rakkor.uk"
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-08 21:27:08
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 52.47.125.32 (ec2-52-47-125-32.eu-west-3.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.47.125.32 (ec2-52-47-125-32.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 08 17:27:01.417041 2025] [security2:error] [pid 17219:tid 17219] [client 52.47.125.32:52145] [client 52.47.125.32] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "facebook.teenyb.com"] [uri "/sftp-config.json"] [unique_id "aB0hpeMYb8CosxYfXlvwkgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-08 20:44:15
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 52.47.125.32 (ec2-52-47-125-32.eu-west-3.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.47.125.32 (ec2-52-47-125-32.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 08 16:44:11.279456 2025] [security2:error] [pid 3484336:tid 3484336] [client 52.47.125.32:52201] [client 52.47.125.32] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "worshipconcert.com"] [uri "/1cfeiz//sftp-config.json"] [unique_id "aB0Xm0Bydjuh75HiWeP5eAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-05-08 20:05:43
(1 year ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-08 20:01:57
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 52.47.125.32 (ec2-52-47-125-32.eu-west-3.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.47.125.32 (ec2-52-47-125-32.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 08 16:01:52.365625 2025] [security2:error] [pid 3937462:tid 3937462] [client 52.47.125.32:60853] [client 52.47.125.32] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "festival.bluegrassexpressband.com"] [uri "/sftp-config.json"] [unique_id "aB0NsPn56tt6S9GRFPrOrAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2025-05-08 19:56:10
(1 year ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐ธ๐ช
SkyDancer
2025-05-08 19:38:12
(1 year ago)
Multiple web intrusion attempts or RDP/SSH hacking using wrong credentials. Attack automatically blo ...
show more
Multiple web intrusion attempts or RDP/SSH hacking using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Ai-D
show less
Hacking
Brute-Force
SSH