๐บ๐ธ
TPI-Abuse
2026-09-24 06:40:04
(47 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:39:57.146800 2026] [security2:error] [pid 26051:tid 26051] [client 34.102.9.103:59896] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brokenglasstelecom.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brokenglasstelecom.com"] [uri "/.codex/auth.json.old"] [unique_id "arTFvaVSMqc-wQ5xgxO7pgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-24 04:51:04
(2 hours ago)
34.102.9.103 - - [24/Sep/2026:04:50:03 +0000] "GET /site/.codex/auth.json HTTP/1.1" 403 45963 "-" "c ...
show more
34.102.9.103 - - [24/Sep/2026:04:50:03 +0000] "GET /site/.codex/auth.json HTTP/1.1" 403 45963 "-" "crusader-worker/1.0" "-" edge="34.102.9.103"
34.102.9.103 - - [24/Sep/2026:04:50:03 +0000] "GET /public/.codex/auth.json HTTP/1.1" 403 45971 "-" "crusader-worker/1.0" "-" edge="34.102.9.103"
34.102.9.103 - - [24/Sep/2026:04:50:03 +0000] "GET /.claude/settings.json HTTP/1.1" 403 45971 "-" "crusader-worker/1.0" "-" edge="34.102.9.103"
34.102.9.103 - - [24/Sep/2026:04:50:03 +0000] "GET /.claude/settings.local.json HTTP/1.1" 403 45971 "-" "crusader-worker/1.0" "-" edge="34.102.9.103"
34.102.9.103 - - [24/Sep/2026:04:50:03 +0000] "GET /html/.claude.json HTTP/1.1" 403 45963 "-" "crusader-worker/1.0" "-" edge="34.102.9.103"
...
show less
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-24 03:23:02
(4 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_u ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_ua, ai_secrets, source_backup. Observed by 1 sensor(s); 50 hits.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:39:08
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:39:03.099844 2026] [security2:error] [pid 9303:tid 9303] [client 34.102.9.103:41618] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bencurry.curryfirm.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bencurry.curryfirm.com"] [uri "/.codex/auth.json.bak"] [unique_id "arR_NzhLQ5ZsQLwzm1DdgAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:20:24
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:20:20.408640 2026] [security2:error] [pid 9028:tid 9125] [client 34.102.9.103:60296] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||beckmon.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "beckmon.com"] [uri "/.codex/auth.json.bak"] [unique_id "arR61Edbm6aihMkiuayNMgAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-24 01:19:17
(6 hours ago)
Domain : beckmanunicorn.com
Rule : config
2026-09-24 01:18:23 ***hidden-privacy*** GET /.codex/auth. ...
show more
Domain : beckmanunicorn.com
Rule : config
2026-09-24 01:18:23 ***hidden-privacy*** GET /.codex/auth.json.old - 443 - 34.102.9.103 HTTP/1.1 crusader-worker/1.0 - beckmanunicorn.com 404 0 2 1557 110 480 - -
show less
Hacking
SQL Injection
๐ช๐ธ
pipeline.es
2026-09-23 16:33:04
(14 hours ago)
Web scanning / probing for vulnerable paths | URL: /site/.codex/auth.json | Evidence: atlas-viagens. ...
show more
Web scanning / probing for vulnerable paths | URL: /site/.codex/auth.json | Evidence: atlas-viagens.pt 34.102.9.103 - - [23/Sep/2026:18:31:34 +0200] \"GET /site/.codex/auth.json HTTP/1.1\" 404 23342 \"-\" \"crusader-worker/1.0\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:58:11
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:58:03.831115 2026] [security2:error] [pid 21111:tid 21111] [client 34.102.9.103:39818] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arklahomaflooring.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arklahomaflooring.com"] [uri "/.codex/auth.json.bak"] [unique_id "arPo-zqT-CkW_4QtybqbpwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-09-23 13:07:15
(18 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /.codex/auth.json.old
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ช๐ธ
pipeline.es
2026-09-23 09:55:08
(21 hours ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 08:36:55
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 04:36:51.004072 2026] [security2:error] [pid 2151414:tid 2151414] [client 34.102.9.103:53360] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||angelpc.net|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "angelpc.net"] [uri "/.codex/auth.json.bak"] [unique_id "arOPo3e1oqjEoRcCj6JblgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 08:26:24
(23 hours ago)
Restricted File Access Attempt. Matched phrase "credentials.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-23 07:57:45
(23 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 07:49:25
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.102.9.103 (103.9.102.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 03:49:18.244921 2026] [security2:error] [pid 7890:tid 7890] [client 34.102.9.103:60732] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanureport.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanureport.com"] [uri "/.codex/auth.json.old"] [unique_id "arOEfqGb_Eaory6Q_VanSwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 04:54:19
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /var/www/.codex/auth.json | Evidence: www.aevav.c ...
show more
Web scanning / probing for vulnerable paths | URL: /var/www/.codex/auth.json | Evidence: www.aevav.com 34.102.9.103 - - [23/Sep/2026:06:53:37 +0200] \"GET /var/www/.codex/auth.json HTTP/1.1\" 404 - \"-\" \"crusader-worker/1.0\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack