Anonymous
2026-09-24 03:03:12
(7 hours ago)
Bot / seems abusive / Apache connections: 55
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-24 01:49:06
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ฆ
URAN Publishing Service
2026-09-23 22:19:47
(12 hours ago)
[24/Sep/2026:01:19:47 +0300] -- 136.66.217.76 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[24/Sep/2026:01:19:47 +0300] -- 136.66.217.76 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /files/.codex/auth.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:03:30
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.66.217.76 (76.217.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.217.76 (76.217.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:03:22.219044 2026] [security2:error] [pid 8413:tid 8413] [client 136.66.217.76:39154] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.cynosurephotography.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.cynosurephotography.com"] [uri "/.codex/auth.json.bak"] [unique_id "arQUahlRrNUoDlPIGCFx_gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:12:52
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.66.217.76 (76.217.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.217.76 (76.217.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:12:48.910095 2026] [security2:error] [pid 32216:tid 32216] [client 136.66.217.76:55920] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||asterioland.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "asterioland.com"] [uri "/.codex/auth.json.old"] [unique_id "arP6gPLqgq0KxaoKD_-LbwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-23 14:45:05
(20 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 14:28:16
(20 hours ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-23 07:50:46
(1 day ago)
845 requests with url.path */auth.json
164 requests with url.path *.config/*
Brute-Force
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-23 07:12:29
(1 day ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
Anonymous
2026-09-23 05:54:46
(1 day ago)
[server.tmg.gr] httpd-config-scan: sites=www.aidshep2018.gr,www.aidshep2019.gr,www.aidshep2020.gr,ww ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.aidshep2018.gr,www.aidshep2019.gr,www.aidshep2020.gr,www.aidshep2021.gr; logs=/var/log/httpd/domains/aidshep2018.gr.log,/var/log/httpd/domains/aidshep2019.gr.log,/var/log/httpd/domains/aidshep2020.gr.log; samples=/.codex/auth.json.old | /html/.claude.json | /old/.codex/auth.json
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 05:10:06
(1 day ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 03:09:12
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.66.217.76 (76.217.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.217.76 (76.217.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 23:09:08.515408 2026] [security2:error] [pid 24630:tid 24630] [client 136.66.217.76:56716] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||admin.casaniagara.com.mx.elpais.mx|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "admin.casaniagara.com.mx.elpais.mx"] [uri "/.codex/auth.json.old"] [unique_id "arNC1PMj9y0sULL7dea3ZAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-09-23 02:31:34
(1 day ago)
136.66.217.76 - - [23/Sep/2026:05:31:33 +0300] "GET /.codex/auth.json.old HTTP/1.1" 404 153 "-" "cru ...
show more
136.66.217.76 - - [23/Sep/2026:05:31:33 +0300] "GET /.codex/auth.json.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ซ๐ท
aureliancnx
2026-09-23 01:50:51
(1 day ago)
HTTP Flood
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:38:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.66.217.76 (76.217.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.217.76 (76.217.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:38:36.345245 2026] [security2:error] [pid 10588:tid 10588] [client 136.66.217.76:40964] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||4bearspress.wolter-hausser.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "4bearspress.wolter-hausser.com"] [uri "/.codex/auth.json.old"] [unique_id "arKvDP0tPm51Zub8wrhREQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack