๐บ๐ธ
TPI-Abuse
2026-09-24 01:59:19
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.148.33.52 (52.33.148.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.33.52 (52.33.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:59:12.045906 2026] [security2:error] [pid 4514:tid 4538] [client 34.148.33.52:45456] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bestthingieveratelocations.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bestthingieveratelocations.com"] [uri "/.codex/auth.json.bak"] [unique_id "arSD8IGD1e56mmgYbheuFAAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:53:48
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.148.33.52 (52.33.148.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.33.52 (52.33.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:53:43.349351 2026] [security2:error] [pid 31262:tid 31292] [client 34.148.33.52:45816] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.blipdecor.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.blipdecor.com"] [uri "/.codex/auth.json.old"] [unique_id "arQSJ1V87XB76I5mpweHXgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-23 16:25:01
(1 week ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 09:54:57
(1 week ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 09:08:29
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.148.33.52 (52.33.148.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.33.52 (52.33.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 05:08:21.674491 2026] [security2:error] [pid 3811:tid 3811] [client 34.148.33.52:40386] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anxo.net|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anxo.net"] [uri "/.codex/auth.json.bak"] [unique_id "arOXBbAFlGzlh2tznCoxXwAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-23 08:30:05
(1 week ago)
Bad behaviour
Web Spam
๐ฉ๐ช
LRob
2026-09-23 07:56:17
(1 week ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /bak/.claude/credentials.json (+12 more) | 2026-09-23 07:56 UTC
show less
Hacking
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-23 07:17:33
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 05:46:25
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-23 05:32:33
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-09-23 05:30:17
(1 week ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-09-23 05:05:15
(1 week ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 02:50:32
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.148.33.52 (52.33.148.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.33.52 (52.33.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:50:25.626017 2026] [security2:error] [pid 1678650:tid 1678650] [client 34.148.33.52:47136] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||admcolumbus.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "admcolumbus.com"] [uri "/.codex/auth.json.old"] [unique_id "arM-cdcB0TmKdGNeaQaJVQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 02:50:05
(2 weeks ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
ghostwarriors
2026-09-23 02:20:47
(2 weeks ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack