๐ฆ๐บ
paulshipley.com.au
2026-07-30 01:01:17
(1 week ago)
[Thu Jul 30 11:01:16.642671 2026] [security2:error] [pid 435756] [client 93.185.162.136:59984] [clie ...
show more
[Thu Jul 30 11:01:16.642671 2026] [security2:error] [pid 435756] [client 93.185.162.136:59984] [client 93.185.162.136] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "angleseaarthouse.com.au"] [uri "/sftp-config.json"] [unique_id "amqiXOAkyvaQQcAJ6nvQggAAAAk"]
...
show less
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-29 22:08:57
(1 week ago)
cloudlinux2 fail2ban: 2026-07-30 00:04:38,557 fail2ban.filter [1584]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-30 00:04:38,557 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 93.185.162.136 - 2026-07-30 00:04:38cloudlinux2 fail2ban: 2026-07-30 00:05:58,203 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 2.57.168.14 - 2026-07-30 00:05:57cloudlinux2 fail2ban: 2026-07-30 00:05:58,463 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 2.57.168.14 - 2026-07-30 00:05:57cloudlinux2 fail2ban: 2026-07-30 00:06:42,793 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 65.111.31.131 - 2026-07-30 00:06:41cloudlinux2 fail2ban: 2026-07-30 00:06:52,872 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 65.111.22.157 - 2026-07-30 00:06:52cloudlinux2 fail2ban: 2026-07-30 00:06:52,200 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.3.45.31 - 2026-07-30 00:06:51cloudlinux2 fail2ban: 2026-07-30 00:06:52,497 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 104.207.54.132 - 2026-07-30 00:06:52cloudlinux2
show less
Web App Attack
๐ง๐ช
cmbplf
2026-07-29 20:35:37
(2 weeks ago)
103 requests with url.path *sftp.json
Brute-Force
Bad Web Bot
Anonymous
2026-07-29 17:39:31
(2 weeks ago)
93.185.162.136 - - [29/Jul/2026:17:39:31 +0000] "GET /sftp-config.json HTTP/1.1" 404 4246 "-" "Mozil ...
show more
93.185.162.136 - - [29/Jul/2026:17:39:31 +0000] "GET /sftp-config.json HTTP/1.1" 404 4246 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-07-29 17:25:36
(2 weeks ago)
GET /sftp-config.json HTTP/1.1
Web App Attack
๐ฉ๐ช
4server
2026-07-29 16:06:49
(2 weeks ago)
[WedJul2918:06:48.0131142026][security2:error][pid1766177:tid1766194][client93.185.162.136:0]ModSecu ...
show more
[WedJul2918:06:48.0131142026][security2:error][pid1766177:tid1766194][client93.185.162.136:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\\\\\\\\.vscode/\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1189\"][id\"350593\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-Dataleakage-attempttoaccessstoredvscodepasswords\"][severity\"CRITICAL\"][hostname\"atelier-lara.ch\"][uri\"/.vscode/sftp.json\"][unique_id\"amolGLX17CCCkv0bxXUgUgAAAAU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
SysAdmin Dylan
2026-07-29 01:35:24
(2 weeks ago)
*Port Scan* detected from 93.185.162.136 (ID/Indonesia/-). 11 hits in the last 262 seconds
Brute-Force
๐น๐ท
neron
2026-07-27 22:19:38
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ซ๐ท
Dampen59
2026-07-26 18:27:15
(2 weeks ago)
(cpanel) Failed cPanel login from 93.185.162.136 (ID/Indonesia/-): 5 in the last 3600 secs; Ports: * ...
show more
(cpanel) Failed cPanel login from 93.185.162.136 (ID/Indonesia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-07-26 20:05:13 +0200] info [whostmgrd] 93.185.162.136 - root "POST /login/?login_only=1 HTTP/1.1" FAILED LOGIN whostmgrd: user password incorrect
[2026-07-26 20:11:21 +0200] info [whostmgrd] 93.185.162.136 - root "POST /login/?login_only=1 HTTP/1.1" FAILED LOGIN whostmgrd: user password incorrect
[2026-07-26 20:11:43 +0200] info [whostmgrd] 93.185.162.136 - root "POST /login/?login_only=1 HTTP/1.1" FAILED LOGIN whostmgrd: user password incorrect
[2026-07-26 20:25:13 +0200] info [whostmgrd] 93.185.162.136 - root "POST /login/?login_only=1 HTTP/1.1" FAILED LOGIN whostmgrd: user password incorrect
[2026-07-26 20:27:13 +0200] info [whostmgrd] 93.185.162.136 - root "POST /login/?login_only=1 HTTP/1.1" FAILED LOGIN whostmgrd: user password incorrect
show less
Port Scan
๐ฆ๐บ
nzhost.co.nz
2026-07-23 23:06:38
(2 weeks ago)
$f2bV_matches
Hacking
Brute-Force
๐ณ๐ฟ
Tripwire
2026-07-23 19:45:33
(2 weeks ago)
Scanning for exploits - /.vscode/sftp.json
Web App Attack
๐ฉ๐ช
4server
2026-07-20 20:59:28
(3 weeks ago)
[MonJul2022:59:24.7447402026][security2:error][pid2135218:tid2135225][client93.185.162.136:0]ModSecu ...
show more
[MonJul2022:59:24.7447402026][security2:error][pid2135218:tid2135225][client93.185.162.136:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"aexthesya.ch\"][uri\"/sftp-config.json\"][unique_id\"al6MLAXoQGZ5kbMSrCvgYgAAAQQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 03:43:56
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 93.185.162.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 93.185.162.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 23:43:49.529960 2026] [security2:error] [pid 6585:tid 6585] [client 93.185.162.136:34090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ctrussell.us"] [uri "/sftp-config.json"] [unique_id "al2ZdUxTldMn2NjL21LZ0wAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 02:34:07
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 93.185.162.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 93.185.162.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 22:34:02.037432 2026] [security2:error] [pid 574556:tid 574556] [client 93.185.162.136:41344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graner.us"] [uri "/sftp-config.json"] [unique_id "al2JGkJ4uSxbhzhEQey6JQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 02:16:20
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 93.185.162.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 93.185.162.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 22:16:14.873045 2026] [security2:error] [pid 466139:tid 466139] [client 93.185.162.136:54706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cswiki.us"] [uri "/sftp-config.json"] [unique_id "al2E7u0Zx-Gt43-02Ik2hwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack