Anonymous
2026-09-22 04:02:12
(6 days ago)
Bot / seems abusive / Apache connections: 26
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 02:50:48
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.106.213.7 (7.213.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.106.213.7 (7.213.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:50:44.154169 2026] [security2:error] [pid 18635:tid 18635] [client 34.106.213.7:53890] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ndakno.jazziientertainment.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ndakno.jazziientertainment.com"] [uri "/.codex/auth.json.old"] [unique_id "arHtBL4btsX_NvvTJUgsgwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-09-22 01:10:27
(6 days ago)
*Port Scan* detected from 34.106.213.7 (US/United States/Utah/Salt Lake City/7.213.106.34.bc.googleu ...
show more
*Port Scan* detected from 34.106.213.7 (US/United States/Utah/Salt Lake City/7.213.106.34.bc.googleusercontent.com).
show less
Port Scan
๐ณ๐ฑ
Savvii
2026-09-21 21:42:18
(6 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lunix
2026-09-21 19:13:24
(1 week ago)
Brute-Force
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-21 15:48:04
(1 week ago)
Malicious activity from IP detected: crowdsecurity/http-probing.
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-21 15:01:08
(1 week ago)
excessive HTTP 404 errors
Bad Web Bot
๐ฆ๐น
piqwjdas
2026-09-21 12:47:01
(1 week ago)
{"transaction":{"client_ip":"34.106.213.7","time_stamp":"Mon Sep 21 14:47:00 2026","server_id":"4682 ...
show more
{"transaction":{"client_ip":"34.106.213.7","time_stamp":"Mon Sep 21 14:47:00 2026","server_id":"46824fc494f03034e6b98e26d7a2d7a06b25f0b7","client_port":56802,"host_ip":"212.186.116.154","host_port":443,"unique_id":"178999482074.805111","is_interrupted":true,"request":{"method":"GET","http_version":"1.1","hostname":"ocean-dockge.spiess-vienna.at","uri":"/backup/.codex/auth.json","headers":{"accept":"*/*","user-agent":"crusader-worker/1.0","host":"ocean-dockge.spiess-vienna.at"}},"response":{"http_code":403,"headers":{"Server":"nginx\u0000","Date":"Mon, 21 Sep 2026 12:47:00 GMT","Content-Length":"146","Content-Type":"text/html","Connection":"keep-alive"}},"producer":{"modsecurity":"ModSecurity v3.0.16 (Linux)","connector":"ModSecurity-nginx v1.0.4","secrules_engine":"Enabled","components":["OWASP_CRS/4.30.0-dev\""]},"messages":[{"message":"Restricted File Access Attempt","details":{"match":"Matched \"Operator `PmFromFile' with parameter `restricted-files.data' against variable `REQUEST_F
...
show less
Web App Attack
Anonymous
2026-09-21 11:30:02
(1 week ago)
CrowdSec decision: crowdsecurity/http-probing (origin: crowdsec)
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 06:32:30
(1 week ago)
34.106.213.7 - - [21/Sep/2026:06:32:04 +0000] "GET /data/.claude.json HTTP/1.1" 403 47237 "-" "crusa ...
show more
34.106.213.7 - - [21/Sep/2026:06:32:04 +0000] "GET /data/.claude.json HTTP/1.1" 403 47237 "-" "crusader-worker/1.0" "-" edge="34.106.213.7"
34.106.213.7 - - [21/Sep/2026:06:32:04 +0000] "GET /www/.claude/credentials.json HTTP/1.1" 403 47237 "-" "crusader-worker/1.0" "-" edge="34.106.213.7"
34.106.213.7 - - [21/Sep/2026:06:32:04 +0000] "GET /.config/claude/credentials.json HTTP/1.1" 403 47237 "-" "crusader-worker/1.0" "-" edge="34.106.213.7"
34.106.213.7 - - [21/Sep/2026:06:32:04 +0000] "GET /bak/.codex/auth.json HTTP/1.1" 403 47237 "-" "crusader-worker/1.0" "-" edge="34.106.213.7"
34.106.213.7 - - [21/Sep/2026:06:32:04 +0000] "GET /app/.codex/auth.json HTTP/1.1" 403 47237 "-" "crusader-worker/1.0" "-" edge="34.106.213.7"
...
show less
Web App Attack
Anonymous
2026-09-21 06:06:34
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-21 05:55:04
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ง๐ช
webbie
2026-09-21 05:09:50
(1 week ago)
34.106.213.7 - - [21/Sep/2026:07:09:48 +0200] "GET /bak/.codex/auth.json HTTP/1.1" 404 5220 "-" "cru ...
show more
34.106.213.7 - - [21/Sep/2026:07:09:48 +0200] "GET /bak/.codex/auth.json HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
34.106.213.7 - - [21/Sep/2026:07:09:48 +0200] "GET /old/.claude.json HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
34.106.213.7 - - [21/Sep/2026:07:09:48 +0200] "GET /bak/.claude/credentials.json HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
34.106.213.7 - - [21/Sep/2026:07:09:48 +0200] "GET /backup/.claude/credentials.json HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
34.106.213.7 - - [21/Sep/2026:07:09:48 +0200] "GET /.claude.json HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-21 05:05:59
(1 week ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /bak/.claude/credentials.json (+14 more) | 2026-09-21 05:05 UTC
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 05:03:19
(1 week ago)
Web attack/malicious scanning detected
Web App Attack