๐จ๐ฆ
SSH-Admin
2026-09-22 09:00:15
(1 week ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-09-22 05:15:02
(1 week ago)
Probing for Exploits on ns45
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 04:18:23
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 104.155.99.106 (106.99.155.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 104.155.99.106 (106.99.155.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:18:18.480375 2026] [security2:error] [pid 16893:tid 16893] [client 104.155.99.106:43488] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||notimallinckrodt.com.ar.misterflores.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "notimallinckrodt.com.ar.misterflores.com"] [uri "/.codex/auth.json.old"] [unique_id "arIBimdvGrOJnK4Wp7YrpgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-22 01:38:10
(1 week ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 104.155.99.106 (BE/Belgium/106.99.155.104 ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 104.155.99.106 (BE/Belgium/106.99.155.104.bc.googleusercontent.com)
show less
Hacking
๐ฉ๐ช
BlueWire Hosting
2026-09-22 00:02:31
(1 week ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐บ๐ธ
mnsf
2026-09-21 23:06:05
(1 week ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
Anonymous
2026-09-21 21:07:03
(1 week ago)
Automated web scanner. Requested suspicious paths: /bak/.claude/credentials.json | /codex/auth.json ...
show more
Automated web scanner. Requested suspicious paths: /bak/.claude/credentials.json | /codex/auth.json | /app/.codex/auth.json | /.claude.json | /.codex/auth.json~ | /root/.codex/auth.json | /api/.codex/auth.json | /opt/.codex/auth.json | /.codex/auth.json.old | /.codex/auth.json.save. UTC: 2026-09-21 20:40:37.
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 13:05:03
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
abivia
2026-09-21 11:43:32
(1 week ago)
Abivia WAF trigger: Rule install-fishing: Looking for old installs. uri: /backup/.claude.json
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 11:15:03
(1 week ago)
[ti-27al] Excessive 404 errors (web scanning): 41 suspicious requests detected by fail2ban jail apac ...
show more
[ti-27al] Excessive 404 errors (web scanning): 41 suspicious requests detected by fail2ban jail apache-404. Example: 104.155.99.106 - - [21/Sep/2026:13:14:58 +0200] "GET /.codex/auth.json HTTP/1.1" 404 6632 "-" "crusader-worker/1.0"
104.155.99.106 - - [21/Sep/2026:13:14:58 +0200] "GET /.codex/config.json HTTP/1.1" 404 6632 "-" "crusader-worker/1.0"
104.155.99.106 - - [21/Sep/2026:13:14:58 +0200] "GET /.codex/config.toml HTTP/1.1" 404 6632 "-" "crusader-worker/1.0"
104.155.99.106 - - [21/Sep/2026:13:14:58 +0200] "GET /.claude/credentials.json HTTP/1.1" 404 6632 "-" "crusader-worker/1.0"
104.155.99.106 - - [21/Sep/2026:13:14:58 +0200] "GET /.claude/.credentials.json HTTP/1.1" 404 6632 "-" "crusader-worker/1.0"
104.155.99.10
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 11:00:05
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-21 10:59:28
(1 week ago)
104.155.99.106 - - [21/Sep/2026:10:59:28 +0000] "GET /.codex/config.toml HTTP/1.1" 404 162 "-" "crus ...
show more
104.155.99.106 - - [21/Sep/2026:10:59:28 +0000] "GET /.codex/config.toml HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
104.155.99.106 - - [21/Sep/2026:10:59:28 +0000] "GET /.codex/auth.json HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ญ๐บ
DumaNet
2026-09-21 07:32:00
(1 week ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 21. 09:02:14
Source IP: 104.15 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 21. 09:02:14
Source IP: 104.155.99.106
Portion of the log(s):
104.155.99.106 - [21/Sep/2026:09:02:14 +0200] "GET /backup/.codex/auth.json HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
104.155.99.106 - [21/Sep/2026:09:02:14 +0200] "GET /.claude/.credentials.json HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
104.155.99.106 - [21/Sep/2026:09:02:14 +0200] "GET /.codex/config.toml HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
104.155.99.106 - [21/Sep/2026:09:02:14 +0200] "GET /.claude/settings.local.json HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
104.155.99.106 - [21/Sep/2026:09:02:14 +0200] "GET /old/.claude.json HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
104.155.99.106 - [21/Sep/2026:09:02:14 +0200] "GET /public/.codex/auth.json HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
104.155.99.106 - [21/Sep/2026:09:02:14 +0200] "GET /.claude/credentials.json HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
104.155.99.106 - [21/Sep/2026:09:02:14 +0200
show less
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 06:24:05
(1 week ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-09-21 04:39:45
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking