๐ณ๐ฑ
Cloud86 B.V.
2026-09-24 08:51:01
(3 minutes ago)
categories: DDoS Attack
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:36:33
(17 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.158.220.97 (97.220.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.220.97 (97.220.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:36:27.472557 2026] [security2:error] [pid 23415:tid 23425] [client 34.158.220.97:54558] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||caarp.tusappsonline.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "caarp.tusappsonline.com"] [uri "/.codex/auth.json.bak"] [unique_id "arThC4mF68oNI2DrvoETCwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-24 04:20:03
(4 hours ago)
Bruteforce
Bad Web Bot
๐ฉ๐ช
macrob
2026-09-24 03:13:33
(5 hours ago)
2026/09/24 03:13:32 [error] 2347326#2347326: *30345483 access forbidden by rule, client: 34.158.220. ...
show more
2026/09/24 03:13:32 [error] 2347326#2347326: *30345483 access forbidden by rule, client: 34.158.220.97, server: bin.partners, request: "GET /.codex/config.json HTTP/2.0", host: "bin.partners"
2026/09/24 03:13:32 [error] 2347325#2347325: *30345484 access forbidden by rule, client: 34.158.220.97, server: bin.partners, request: "GET /.codex/auth.json HTTP/2.0", host: "bin.partners"
2026/09/24 03:13:32 [error] 2347325#2347325: *30345485 access forbidden by rule, client: 34.158.220.97, server: bin.partners, request: "GET /.codex/auth.json.bak HTTP/2.0", host: "bin.partners"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:03:38
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.158.220.97 (97.220.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.220.97 (97.220.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:03:30.999414 2026] [security2:error] [pid 23916:tid 23916] [client 34.158.220.97:35802] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bikinipageone.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bikinipageone.com"] [uri "/.codex/auth.json.bak"] [unique_id "arSTAt2KSi8VuE4zvRWKHgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 00:35:02
(8 hours ago)
723 requests with url.path */auth.json
254 requests with url.path *credentials.json
109 requests ...
show more
723 requests with url.path */auth.json
254 requests with url.path *credentials.json
109 requests with url.path *.config/*
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
mnsf
2026-09-23 21:05:21
(11 hours ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
Anonymous
2026-09-23 16:13:04
(16 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-23 05:40:08
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 01:01:49
(1 day ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 20:05:38
(1 day ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:19:44
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.158.220.97 (97.220.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.158.220.97 (97.220.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:19:37.748116 2026] [security2:error] [pid 14972:tid 14972] [client 34.158.220.97:45842] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||hills-tax.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hills-tax.com"] [uri "/.codex/auth.json.bak"] [unique_id "arI6GTjzDSu5JE6PIwEQXgAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack