๐บ๐ธ
TPI-Abuse
2026-09-22 03:12:56
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.175.18.25 (25.18.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.18.25 (25.18.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 23:12:49.184398 2026] [security2:error] [pid 3439:tid 3439] [client 34.175.18.25:44740] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blackballprojects.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blackballprojects.com"] [uri "/.codex/auth.json.bak"] [unique_id "arHyMUBEHwJ16kwraY9X0QAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-22 02:44:49
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:33:21
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.175.18.25 (25.18.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.18.25 (25.18.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:33:16.793622 2026] [security2:error] [pid 32187:tid 32187] [client 34.175.18.25:42930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||epscalltoaction.org|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "epscalltoaction.org"] [uri "/.codex/auth.json.bak"] [unique_id "arGwrJmZTukNgUU8nMd_gAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-21 21:35:54
(2 days ago)
Repeated requests for suspicious nonexistent URLs, for example: /.claude.json (HTTP/1.1 port 443, us ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /.claude.json (HTTP/1.1 port 443, user agent: "crusader-worker/1.0")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:11:20
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.175.18.25 (25.18.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.18.25 (25.18.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:11:13.789546 2026] [security2:error] [pid 5531:tid 5531] [client 34.175.18.25:40708] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rachellaitman.michaelholdengc.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rachellaitman.michaelholdengc.com"] [uri "/.codex/auth.json.bak"] [unique_id "arGPYdMrX8RjivsiEHOukgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
realstuffie
2026-09-21 19:46:55
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 17:11:38
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-21 13:44:23
(2 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-21 13:37:52
(2 days ago)
excessive HTTP 404 errors
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-21 13:09:57
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
mr.joecat
2026-09-21 07:21:01
(2 days ago)
34.175.18.25 - - [21/Sep/2026:09:21:00 +0200] "GET /.claude/settings.json HTTP/1.1" 404 153 "-" "cru ...
show more
34.175.18.25 - - [21/Sep/2026:09:21:00 +0200] "GET /.claude/settings.json HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:09:21:00 +0200] "GET /.config/claude/credentials.json HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:09:21:00 +0200] "GET /backup/.codex/auth.json HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:09:21:00 +0200] "GET /.codex/config.toml HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:09:21:00 +0200] "GET /.codex/config.json HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-21 06:50:15
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-21 06:44:15
(2 days ago)
34.175.18.25 - - [21/Sep/2026:08:44:11 +0200] "GET /wwwroot/.codex/auth.json HTTP/1.1" 404 30755 "-" ...
show more
34.175.18.25 - - [21/Sep/2026:08:44:11 +0200] "GET /wwwroot/.codex/auth.json HTTP/1.1" 404 30755 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:08:44:11 +0200] "GET /tmp/.codex/auth.json HTTP/1.1" 404 30755 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:08:44:11 +0200] "GET /files/.codex/auth.json HTTP/1.1" 404 30754 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:08:44:11 +0200] "GET /.claude/settings.json HTTP/1.1" 404 30755 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:08:44:11 +0200] "GET /.claude/.credentials.json HTTP/1.1" 404 29549 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:08:44:11 +0200] "GET /config/.codex/auth.json HTTP/1.1" 404 29550 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:08:44:11 +0200] "GET /srv/.codex/auth.json HTTP/1.1" 404 30755 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:08:44:11 +0200] "GET /.codex/config.json HTTP/1.1" 404 30754 "-" "crusader-worker/1.0"
34.175.18.25 - - [21/Sep/2026:08:44
show less
Bad Web Bot
๐ณ๐ฑ
pixelXp
2026-09-21 06:27:23
(2 days ago)
Reason:15 (Hacking), Via: www.pixelxp.com/old/.claude.json, Message: Escalatie: cumulatieve score=77 ...
show more
Reason:15 (Hacking), Via: www.pixelxp.com/old/.claude.json, Message: Escalatie: cumulatieve score=77 (drempel=75); laatste score=21; Signals: GET met querystring zonder Sec-Fetch-* headers [+5] | Accept-header is enkel '*/*' โ scripting-tool standaard [+8] | Ontbrekende browser-headers (2/3: Accept, Accept-Language, Accept-Encoding) [+8]
show less
Hacking