๐ซ๐ฎ
paissangroup
2026-08-24 08:59:25
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-24 08:04:22
(2 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: \.vscode (Match: .vscode)
show less
Hacking
Web App Attack
๐ซ๐ฎ
YF
2026-08-24 04:00:43
(2 days ago)
Config JSON probe
Web App Attack
๐บ๐ธ
nyt
2026-08-24 01:01:01
(2 days ago)
Deploy Config Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 21:47:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 64.225.43.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.225.43.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 17:47:46.495739 2026] [security2:error] [pid 20182:tid 20190] [client 64.225.43.73:54215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nothingwithoutwater.com"] [uri "/sftp-config.json"] [unique_id "aotqgkbc996ePfNVAYc59wAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ecode hosting
2026-08-23 17:07:04
(2 days ago)
Domain : anahtarhastanesi.com
Rule : config
2026-08-23 17:05:44 10.100.1.20 GET /.vscode/sftp.json - ...
show more
Domain : anahtarhastanesi.com
Rule : config
2026-08-23 17:05:44 10.100.1.20 GET /.vscode/sftp.json - 80 - 64.225.43.73 HTTP/1.1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36 - www.anahtarhastanesi.com 301 0 0 367 278 245 - -
show less
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-23 11:41:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 64.225.43.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.225.43.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:40:58.449907 2026] [security2:error] [pid 5882:tid 5882] [client 64.225.43.73:60145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trilliantsolutions.com"] [uri "/sftp-config.json"] [unique_id "aorcSpih2R_3jmxj8UmnlAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 05:56:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 64.225.43.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.225.43.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:56:06.973210 2026] [security2:error] [pid 8444:tid 8444] [client 64.225.43.73:52904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "normteslaa.com"] [uri "/sftp-config.json"] [unique_id "aoqLdtM9VsmhW-bCYqOe1QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DocNetzwerk
2026-08-23 01:08:49
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 64.225.43.73 (US/United States/-)
SQL Injection
๐ซ๐ท
Baking333
2026-08-22 23:21:40
(3 days ago)
[redacted] 64.225.43.73 - - [23/Aug/2026:00:21:39 +0100] "GET /.vscode/[redacted] HTTP/1.1" 301 552 ...
show more
[redacted] 64.225.43.73 - - [23/Aug/2026:00:21:39 +0100] "GET /.vscode/[redacted] HTTP/1.1" 301 552 0/134 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" [redacted] 64.225.43.73 - - [23/Aug/2026:00:21:39 +0100] "GET /[redacted] HTTP/1.1" 301 550 0/151 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
RamSet
2026-08-22 22:22:33
(3 days ago)
[pit,ycr] HTTP-Probe on port 443 (via domain). 2 distinct paths probed in 3s. Sustained 5 req/min. P ...
show more
[pit,ycr] HTTP-Probe on port 443 (via domain). 2 distinct paths probed in 3s. Sustained 5 req/min. Paths: /.vscode/sftp.json, /sftp-config.json
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 16:25:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 64.225.43.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.225.43.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 12:25:40.707233 2026] [security2:error] [pid 12480:tid 12480] [client 64.225.43.73:55137] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hawaiireservations.com"] [uri "/sftp-config.json"] [unique_id "aonNhFAphEDH5i3t8JtJlQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-22 16:20:35
(3 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.vscode/sftp.json (+1 more)
show less
Hacking
Web App Attack
๐ฉ๐ช
4server
2026-08-22 14:34:53
(3 days ago)
[SatAug2216:34:46.7259892026][security2:error][pid2572365:tid2572380][client64.225.43.73:0]ModSecuri ...
show more
[SatAug2216:34:46.7259892026][security2:error][pid2572365:tid2572380][client64.225.43.73:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\\\\\\\\.vscode/\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1189\"][id\"350593\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-Dataleakage-attempttoaccessstoredvscodepasswords\"][severity\"CRITICAL\"][hostname\"ilmiotrentino.it\"][uri\"/.vscode/sftp.json\"][unique_id\"aomzhsLQkISbb2moEPiBQQAAAEQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 12:35:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 64.225.43.73 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.225.43.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:35:33.528507 2026] [security2:error] [pid 11149:tid 11149] [client 64.225.43.73:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webfrog.ws"] [uri "/sftp-config.json"] [unique_id "aomXlZ6KpZN--pJbGd-QLgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack