๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-24 07:50:25
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 07:06:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:06:23.191682 2026] [security2:error] [pid 26740:tid 26740] [client 34.13.13.116:47984] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||budgetbyron.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "budgetbyron.com"] [uri "/.codex/auth.json.old"] [unique_id "arTL73b2KHHvoAfmm2iPOgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:24:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:24:23.747587 2026] [security2:error] [pid 19746:tid 19746] [client 34.13.13.116:52964] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brianchancemusic.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brianchancemusic.com"] [uri "/.codex/auth.json.bak"] [unique_id "arTCFydM1v4-T1MeE52yCgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:31:34
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:31:30.307383 2026] [security2:error] [pid 20432:tid 20432] [client 34.13.13.116:40756] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blog.ptr.com.post-therapyreconditioning.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blog.ptr.com.post-therapyreconditioning.com"] [uri "/.codex/auth.json.bak"] [unique_id "arSnopedFFUsMULEC8UDSgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SiyCah
2026-09-24 03:00:03
(1 day ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-23 19:27:30
(1 day ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.claude/credentials.json (+8 more) | 2026-09-23 19:27 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-23 19:21:36
(1 day ago)
20 attempts against mh_ha-misbehave-ban on pf221106
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Nicos
2026-09-23 17:20:32
(1 day ago)
2026-09-23T19:20:31.044029+02:00 PhoenixNas 4b557cefc297[346903]: {"auth_via": "unauthenticated", "d ...
show more
2026-09-23T19:20:31.044029+02:00 PhoenixNas 4b557cefc297[346903]: {"auth_via": "unauthenticated", "domain_url": "Redacted", "event": "/old/.codex/auth.json", "host": "Redacted", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 477194, "remote": "34.13.13.116", "request_id": "fd3355b9c18c474c881f86a016f0bed0", "runtime": 758, "schema_name": "public", "scheme": "https", "status": 404, "timestamp": "2026-09-23T17:20:31.043821", "user": "", "user_agent": "crusader-worker/1.0"}
2026-09-23T19:20:31.048748+02:00 PhoenixNas 4b557cefc297[346903]: {"auth_via": "unauthenticated", "domain_url": "Redacted", "event": "/app/.codex/auth.json", "host": "Redacted", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 477194, "remote": "34.13.13.116", "request_id": "3c6022848fbe4b77b41f88123321322c", "runtime": 745, "schema_name": "public", "scheme": "https", "status": 404, "timestamp": "2026-09-23T17:20:31.048619", "user": "", "user_age
...
show less
Hacking
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-09-23 16:47:25
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:06:30
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:06:22.287885 2026] [security2:error] [pid 10245:tid 10245] [client 34.13.13.116:35472] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aroilcontrolsystem.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aroilcontrolsystem.com"] [uri "/.codex/auth.json.bak"] [unique_id "arPq7mxTP1i-w7tHYNt1DgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 12:20:13
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 08:20:08.267843 2026] [security2:error] [pid 10901:tid 10901] [client 34.13.13.116:55982] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||appalachianfolkmagician.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "appalachianfolkmagician.com"] [uri "/.codex/auth.json.bak"] [unique_id "arPD-K8RDeKkexzM5R5AkAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
mgarofano80
2026-09-23 11:46:43
(1 day ago)
Brute-Force
Web App Attack
๐บ๐ธ
grassyloki
2026-09-23 08:41:00
(2 days ago)
Credential-file probe using a 'crusader-worker/1.0' user agent sending repeated GETs for Codex/Claud ...
show more
Credential-file probe using a 'crusader-worker/1.0' user agent sending repeated GETs for Codex/Claude a host and credential files, all returned 403.
Target: HTTP 80 secret/credential-file probes: /htdocs/.codex/a host, /old/.claude/credentials.json, /html/.codex/a host, /.config/claude/credentials.json
Seen: 2026-09-23 04:41 EDT
- 2026-09-23 04:41:10: GET /htdocs/.codex/a host -> 403, UA 'crusader-worker/1.0'
- 2026-09-23 04:41:10: GET /old/.claude/credentials.json -> 403, UA 'crusader-worker/1.0'
- 2026-09-23 04:41:10: GET /html/.codex/a host -> 403 and GET /.config/claude/credentials.json -> 403, UA 'crusader-worker/1.0'
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 07:32:43
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.13.13.116 (116.13.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 03:32:37.010846 2026] [security2:error] [pid 8424:tid 8424] [client 34.13.13.116:57448] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aluminatrailers.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aluminatrailers.com"] [uri "/.codex/auth.json.old"] [unique_id "arOAlYKGmEDClYxNlyP6mgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-23 06:21:22
(2 days ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack