๐บ๐ธ
TPI-Abuse
2026-09-24 09:00:37
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:00:31.214429 2026] [security2:error] [pid 20157:tid 20157] [client 34.159.43.229:50930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||calstarsfarm.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "calstarsfarm.com"] [uri "/.codex/auth.json.bak"] [unique_id "arTmr3rOobgXO2ev_HrugQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:31:25
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:31:17.829823 2026] [security2:error] [pid 21536:tid 21536] [client 34.159.43.229:59798] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||butterflygolem.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "butterflygolem.com"] [uri "/.codex/auth.json.bak"] [unique_id "arTRxWulWm3EP2pdUgx-FAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-24 06:05:23
(1 week ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 05:15:53
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:15:46.531699 2026] [security2:error] [pid 25186:tid 25186] [client 34.159.43.229:48654] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bogartphotography.sisix.net|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bogartphotography.sisix.net"] [uri "/.codex/auth.json.old"] [unique_id "arSyApTzzWXG7xuP9hylNQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-09-24 01:18:21
(1 week ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ซ๐ฎ
botwork.se
2026-09-23 21:43:08
(1 week ago)
{"level":"info","ts":"2026-09-23T21:43:06Z","logger":"http.log.access.log5","msg":"handled request", ...
show more
{"level":"info","ts":"2026-09-23T21:43:06Z","logger":"http.log.access.log5","msg":"handled request","request":{"remote_ip":"34.159.43.229","remote_port":"34914","client_ip":"34.159.43.229","proto":"HTTP/1.1","method":"GET","host":"awty.botwork.se","uri":"/old/.claude.json","headers":{"Accept":["*/*"],"User-Agent":["crusader-worker/1.0"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"awty.botwork.se","ech":false}},"bytes_read":0,"user_id":"","duration":0.001455767,"size":146,"status":404,"resp_headers":{"Strict-Transport-Security":["max-age=31536000"],"Via":["1.1 Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Access-Control-Allow-Methods":["GET, POST, OPTIONS"],"Server":["nginx"],"Content-Length":["146"],"Permissions-Policy":["interest-cohort=()"],"Date":["Wed, 23 Sep 2026 21:43:06 GMT"],"Content-Type":["text/html"],"Access-Control-Allow-Origin":["*"],"Access-Control-Allow-Headers":["Accept,Authorization,Cache-Control,Content-Type,DNT,If-Modi
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:12:14
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:12:09.925949 2026] [security2:error] [pid 32540:tid 32540] [client 34.159.43.229:41280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.usaangelinvestors.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.usaangelinvestors.com"] [uri "/.codex/auth.json.bak"] [unique_id "arQkiQtRswwNWmFc8dXuTgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:56:04
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:55:59.672618 2026] [security2:error] [pid 20949:tid 20949] [client 34.159.43.229:59206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.scc1.us|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.scc1.us"] [uri "/.codex/auth.json.bak"] [unique_id "arQgv5Gt29mpG5a7KZkdgwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:37:09
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:37:01.506139 2026] [security2:error] [pid 17468:tid 17468] [client 34.159.43.229:43754] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||archief.org|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "archief.org"] [uri "/.codex/auth.json.bak"] [unique_id "arPkDYbYH1G_rCovtRZTOgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 14:34:22
(1 week ago)
[ti-10al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-10al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.159.43.229 - - [23/Sep/2026:16:34:13 +0200] "GET /old/.config/codex/auth.json HTTP/1.1" 404 59019 "-" "crusader-worker/1.0"
34.159.43.229 - - [23/Sep/2026:16:34:13 +0200] "GET /files/.codex/auth.json HTTP/1.1" 404 59019 "-" "crusader-worker/1.0"
34.159.43.229 - - [23/Sep/2026:16:34:13 +0200] "GET /www/.codex/auth.json HTTP/1.1" 404 59019 "-" "crusader-worker/1.0"
34.159.43.229 - - [23/Sep/2026:16:34:13 +0200] "GET /root/.codex/auth.json HTTP/1.1" 404 72231 "-" "crusader-worker/1.0"
34.159.43.229 - - [23/Sep/2026:16:34:13 +0200] "GET /.codex/auth.json.bak HTTP/1.1" 404 72230 "-" "crusader-worker/1.0"
34.159.43.229 - - [23/
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 12:23:21
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 08:23:18.546560 2026] [security2:error] [pid 4272:tid 4272] [client 34.159.43.229:35006] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||appalachianstomp.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "appalachianstomp.com"] [uri "/.codex/auth.json.old"] [unique_id "arPEtq-7AC6_B4OPLNwKDwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
hu22am
2026-09-23 10:06:25
(1 week ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/.codex/auth.json ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/.codex/auth.json via rule: /config
show less
Web App Attack
Bad Web Bot
๐ฎ๐น
VHosting
2026-09-23 08:50:06
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 07:02:43
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.43.229 (229.43.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 03:02:37.865378 2026] [security2:error] [pid 17926:tid 17926] [client 34.159.43.229:58402] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alkymera.ahijado.org|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alkymera.ahijado.org"] [uri "/.codex/auth.json.bak"] [unique_id "arN5jXWbh7ra9Pdcd8TYFQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-23 01:41:07
(1 week ago)
Domain : accountant.breeze.business
Rule : hack
2026-09-23 01:38:21 ***hidden-privacy*** GET /.codex ...
show more
Domain : accountant.breeze.business
Rule : hack
2026-09-23 01:38:21 ***hidden-privacy*** GET /.codex/auth.json.bak - 443 - 34.159.43.229 HTTP/1.1 crusader-worker/1.0 - accountant.breeze.business 403 0 0 1462 118 1086 - -
show less
Hacking
SQL Injection
Brute-Force