๐ฌ๐ง
openstrike.co.uk
2026-06-12 05:14:36
(2 hours ago)
2 attacks on password grabbing URLs:
GET /.vscode/sftp.json HTTP/1.1
Hacking
๐จ๐ญ
4server
2026-06-11 21:41:41
(9 hours ago)
[ThuJun1123:41:34.3390782026][security2:error][pid1047678:tid1047985][client93.152.43.14:0]ModSecuri ...
show more
[ThuJun1123:41:34.3390782026][security2:error][pid1047678:tid1047985][client93.152.43.14:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\\\\\\\\.vscode/\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1189\"][id\"350593\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-Dataleakage-attempttoaccessstoredvscodepasswords\"][severity\"CRITICAL\"][hostname\"dc-graphicart.com\"][uri\"/.vscode/sftp.json\"][unique_id\"aisrjt8SVb7OHvhR2DiunAAAAQo\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 19:16:07
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedb ...
show more
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedbroadband.co.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 15:16:03.194940 2026] [security2:error] [pid 12176:tid 12176] [client 93.152.43.14:8864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daydar.net"] [uri "/sftp-config.json"] [unique_id "aisJc23JuJgID2esixaNtQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 17:12:33
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedb ...
show more
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedbroadband.co.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 13:12:24.383853 2026] [security2:error] [pid 6215:tid 6215] [client 93.152.43.14:21506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidnevue.com"] [uri "/sftp-config.json"] [unique_id "airseJHZQxuT_geHp1SFsQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 09:32:20
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedb ...
show more
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedbroadband.co.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 05:32:14.744908 2026] [security2:error] [pid 18340:tid 18340] [client 93.152.43.14:8358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dartylife.com"] [uri "/sftp-config.json"] [unique_id "aiqAnsqrgD2VkVo4yl7sOQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Yosi
2026-06-11 08:51:55
(22 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-11 08:38:01
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedb ...
show more
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedbroadband.co.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 04:37:56.675852 2026] [security2:error] [pid 8435:tid 8435] [client 93.152.43.14:18334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darkstarsystems.net"] [uri "/sftp-config.json"] [unique_id "aipz5HxAm9GmQWgu0KCPFAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 08:02:36
(23 hours ago)
(mod_security) mod_security (id:210580) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedb ...
show more
(mod_security) mod_security (id:210580) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedbroadband.co.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 04:02:28.613512 2026] [security2:error] [pid 2801:tid 2801] [client 93.152.43.14:38010] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "sftp-config.json" at REQUEST_COOKIES:handl_landing_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||darkalleyproductions.com|F|2"] [data "Matched Data: sftp-config.json found within REQUEST_COOKIES:handl_landing_page: http:/daretorewild.com/sftp-config.json"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "darkalleyproductions.com"] [uri "/.vscode/sftp.json"] [unique_id "aiprlOXJO1NKphKiJ26GqQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 05:58:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedb ...
show more
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedbroadband.co.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 01:58:10.843913 2026] [security2:error] [pid 13953:tid 13953] [client 93.152.43.14:27396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danteolalaw.com"] [uri "/sftp-config.json"] [unique_id "aipOcs84dB3UwyLF3r8L6QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 05:26:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedb ...
show more
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedbroadband.co.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 01:26:26.080113 2026] [security2:error] [pid 27658:tid 27658] [client 93.152.43.14:29808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dannyvanrijswijk.com"] [uri "/sftp-config.json"] [unique_id "aipHAr8X1ph0et6PYcJtagAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 20:50:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedb ...
show more
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedbroadband.co.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:50:43.175038 2026] [security2:error] [pid 13321:tid 13321] [client 93.152.43.14:45500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dailybeautysupply.com"] [uri "/sftp-config.json"] [unique_id "ainOI2hbNSyW406maay7lAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 19:05:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedb ...
show more
(mod_security) mod_security (id:210492) triggered by 93.152.43.14 (93-152-43-14.supportspan.managedbroadband.co.uk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 15:05:39.699755 2026] [security2:error] [pid 13570:tid 13570] [client 93.152.43.14:8198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daebakdesign.com"] [uri "/sftp-config.json"] [unique_id "aim1g95Xq4Pv5kvGkOLaCQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack