๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 05:07:31
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
consul.to
2026-09-22 05:00:08
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:52:17
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.69.237.4 (4.237.69.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.237.4 (4.237.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:52:10.832712 2026] [security2:error] [pid 12487:tid 12487] [client 136.69.237.4:35610] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||inmaine.aromatherapyricebags.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "inmaine.aromatherapyricebags.com"] [uri "/.codex/auth.json.bak"] [unique_id "arHfSsQsouTXdlX_9fOcrwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-22 01:48:04
(11 hours ago)
212 requests with url.path */auth.json
Brute-Force
Bad Web Bot
๐ซ๐ท
โจ
2026-09-22 01:20:15
(11 hours ago)
Domain : robertburton.info
Rule : config
2026-09-22 01:18:07 ***hidden-privacy***46 GET /.codex/auth ...
show more
Domain : robertburton.info
Rule : config
2026-09-22 01:18:07 ***hidden-privacy***46 GET /.codex/auth.json - 443 - 136.69.237.4 HTTP/1.1 crusader-worker/1.0 - robertburton.info 404 0 2 1476 105 424 - -
show less
Hacking
SQL Injection
Anonymous
2026-09-22 00:15:34
(12 hours ago)
Automatically blocked after 50 security events. Observed sensitive configuration-file probes. Source ...
show more
Automatically blocked after 50 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:31:05
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.69.237.4 (4.237.69.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.237.4 (4.237.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:31:01.451612 2026] [security2:error] [pid 10715:tid 10715] [client 136.69.237.4:45192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||liquid-libido.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "liquid-libido.com"] [uri "/.codex/auth.json.bak"] [unique_id "arGUBU8RHx0Ydz0kfUcIbgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:46:00
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.69.237.4 (4.237.69.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.237.4 (4.237.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:45:54.560825 2026] [security2:error] [pid 5333:tid 5468] [client 136.69.237.4:34018] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.workbykathryn.workconfident.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.workbykathryn.workconfident.com"] [uri "/.codex/auth.json.old"] [unique_id "arGJcpnaiyghr0xn6qY9fwAAAYI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 12:10:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-21 12:08:52
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-21 10:42:52
(1 day ago)
20 attempts against mh-misbehave-ban on solar
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 10:41:11
(1 day ago)
[ti-22al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-22al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 136.69.237.4 - - [21/Sep/2026:12:40:25 +0200] "GET /bak/.codex/auth.json HTTP/1.1" 404 98685 "-" "crusader-worker/1.0"
136.69.237.4 - - [21/Sep/2026:12:40:25 +0200] "GET /.claude/settings.local.json HTTP/1.1" 404 98685 "-" "crusader-worker/1.0"
136.69.237.4 - - [21/Sep/2026:12:40:25 +0200] "GET /.codex/config.json HTTP/1.1" 404 101501 "-" "crusader-worker/1.0"
136.69.237.4 - - [21/Sep/2026:12:40:25 +0200] "GET /backup/.claude/credentials.json HTTP/1.1" 404 101501 "-" "crusader-worker/1.0"
136.69.237.4 - - [21/Sep/2026:12:40:25 +0200] "GET /backup/.claude.json HTTP/1.1" 404 101501 "-" "crusader-worker/1.0"
136.69.237.4 - - [21/Sep/2026:12:40:25 +0200] "GET /.claude.json HTTP/1.1" 404 101501 "-" "crusader-wor
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 08:29:24
(1 day ago)
20 attempts against mh-misbehave-ban on pf102939
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 08:05:36
(1 day ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ฉ๐ช
sojan
2026-09-21 03:01:09
(1 day ago)
136.69.237.4 - - [21/Sep/2026:05:01:08 +0200] "GET /root/.codex/auth.json HTTP/1.1" 444 0 "-" "crusa ...
show more
136.69.237.4 - - [21/Sep/2026:05:01:08 +0200] "GET /root/.codex/auth.json HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
136.69.237.4 - - [21/Sep/2026:05:01:08 +0200] "GET /.codex/auth.json HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
136.69.237.4 - - [21/Sep/2026:05:01:08 +0200] "GET /uploads/.codex/auth.json HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Web App Attack