🇺🇸
TPI-Abuse
2026-09-05 20:57:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:57:15.993946 2026] [security2:error] [pid 3505773:tid 3505854] [client 94.237.76.68:54654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lisabee.net"] [uri "/sftp-config.json"] [unique_id "apyCKycrIQhcuqFjqhW6VwAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:37:53
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:37:49.482685 2026] [security2:error] [pid 30727:tid 30758] [client 94.237.76.68:55188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "losersoftheyear.net"] [uri "/sftp-config.json"] [unique_id "apx9nVyjTaewCShlwzexDgAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
LMAS
2026-09-05 18:52:09
(4 hours ago)
Automated scan detected. Probe type: Zero-Day/Wildcard Probe. Requested: /sftp-config.json — Honeypo ...
show more
Automated scan detected. Probe type: Zero-Day/Wildcard Probe. Requested: /sftp-config.json — Honeypot triggered.
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 18:36:16
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 14:36:12.814480 2026] [security2:error] [pid 23076:tid 23076] [client 94.237.76.68:55783] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lisarlee.com"] [uri "/sftp-config.json"] [unique_id "apxhHBQh-lPKonRQf8CfLgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 17:42:42
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
paissangroup
2026-09-05 17:35:07
(5 hours ago)
Multiple WAF Violations
Web App Attack
🇨🇦
polycoda
2026-09-05 15:57:19
(6 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ❌ Excessive 40X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-05 15:47:00
(7 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-05 12:08:00
(10 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 11:45:34
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 07:45:29.243279 2026] [security2:error] [pid 7135:tid 7135] [client 94.237.76.68:60454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lockyers.com"] [uri "/sftp-config.json"] [unique_id "apwA2UQi9ZUeMLqU_rc6ogAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-05 10:15:26
(12 hours ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
mnsf
2026-09-05 10:05:29
(12 hours ago)
Too many Status 40X (18)
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-05 09:59:00
(12 hours ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 09:19:03
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 05:18:59.406890 2026] [security2:error] [pid 31033:tid 31033] [client 94.237.76.68:54842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "longhandmedia.com"] [uri "/sftp-config.json"] [unique_id "apveg1mwqv-NgwcBZ8auKwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 08:38:38
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host ...
show more
(mod_security) mod_security (id:210492) triggered by 94.237.76.68 (94-237-76-68.sg-sin1.upcloud.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 04:38:31.382401 2026] [security2:error] [pid 32722:tid 32722] [client 94.237.76.68:54546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.liveinbirminghamalabama.com"] [uri "/sftp-config.json"] [unique_id "apvVB7cwRnOmXBubKsqa7AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack