🇩🇪
FD-IX
2026-09-08 17:00:27
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 15:12:14
(6 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇨🇿
ddw
2026-09-08 08:35:12
(12 hours ago)
Access Violation Attempts - Multiple 403 Forbidden responses.
Hacking
Bad Web Bot
Web App Attack
🇩🇪
lightaffaire
2026-09-08 01:17:27
(20 hours ago)
Sep 8 03:17:26 www.lightaffaire.com 82.21.92.94 - - [08/Sep/2026:03:17:26 +0200] "GET //.vscode/sft ...
show more
Sep 8 03:17:26 www.lightaffaire.com 82.21.92.94 - - [08/Sep/2026:03:17:26 +0200] "GET //.vscode/sftp.json HTTP/1.1" 404 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 15:10:20
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
LRob
2026-09-07 09:09:01
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /sftp-config.json (+1 more) | 2026-09-07 09:09 UTC
show less
Hacking
Web App Attack
🇩🇪
Didier Lagaert
2026-09-06 16:59:55
(2 days ago)
lie-17 : Block hidden directories=>/.vscode/sftp.json(/)
Hacking
🇺🇸
TPI-Abuse
2026-09-06 16:09:51
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 82.21.92.94 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:949110) triggered by 82.21.92.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:09:42.998908 2026] [security2:error] [pid 10507:tid 10507] [client 82.21.92.94:53297] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.servicesafes.com"] [uri "/sftp-config.json"] [unique_id "ap2QRrBvtS-z_XceXpro7wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:53:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 82.21.92.94 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 82.21.92.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:53:05.969404 2026] [security2:error] [pid 5763:tid 5763] [client 82.21.92.94:63054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.voodooshop.com"] [uri "/sftp-config.json"] [unique_id "ap2MYYzTTUnIRGwOUtxS7wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 14:38:07
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
🇧🇪
cmbplf
2026-09-06 09:42:10
(2 days ago)
106 requests with url.path *sftp.json
Brute-Force
Bad Web Bot
🇩🇪
Vegascosmetics
2026-09-06 07:41:41
(2 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: \.vscode (Match: .vscode)
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:06:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 82.21.92.94 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 82.21.92.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:06:01.447611 2026] [security2:error] [pid 24311:tid 24311] [client 82.21.92.94:50463] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dd214chronicle.org"] [uri "/sftp-config.json"] [unique_id "apy8eZxh69GkhJfvT-nmDAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 00:53:46
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:14:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 82.21.92.94 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 82.21.92.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:14:30.948897 2026] [security2:error] [pid 21482:tid 21482] [client 82.21.92.94:56062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aboutagingparents.com"] [uri "/sftp-config.json"] [unique_id "apyURrezCTOJXBcSGGEKDwAAAGU"]
show less
Brute-Force
Bad Web Bot
Web App Attack