๐บ๐ธ
TPI-Abuse
2026-09-22 04:29:18
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.175.207.140 (140.207.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.207.140 (140.207.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:29:14.252635 2026] [security2:error] [pid 56550:tid 56550] [client 34.175.207.140:44986] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arogun.org|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arogun.org"] [uri "/.codex/auth.json.bak"] [unique_id "arIEGs7pWF-mNxTuPuGS_QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-22 03:58:42
(2 days ago)
30 attempts against mh_ha-misbehave-ban on tin
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:51:52
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.175.207.140 (140.207.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.207.140 (140.207.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:51:47.667757 2026] [security2:error] [pid 19824:tid 19843] [client 34.175.207.140:52864] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.landmarkaesthetics.landmarkocchealth.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.landmarkaesthetics.landmarkocchealth.com"] [uri "/.codex/auth.json.bak"] [unique_id "arGm85ANsXN-Rk1tQQjNvAAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Major Hostility
2026-09-21 19:46:28
(3 days ago)
"GET /codex/auth.json HTTP/1.1" 404
"GET /.codex/auth.json.old HTTP/1.1" 404
"GET /.codex/auth.json ...
show more
"GET /codex/auth.json HTTP/1.1" 404
"GET /.codex/auth.json.old HTTP/1.1" 404
"GET /.codex/auth.json HTTP/1.1" 404
"GET /.codex/config.toml HTTP/1.1" 404
"GET /.codex/config.json HTTP/1.1" 404
"GET /.config/codex/auth.json HTTP/1.1" 404
"GET /.codex/auth.json.bak HTTP/1.1" 404
"GET /.codex/auth.json.save HTTP/1.1" 404
"GET /.codex/auth.json~ HTTP/1.1" 404
"GET /.codex/auth.json.txt HTTP/1.1" 404
"GET /.claude.json HTTP/1.1" 404
"GET /.claude/credentials.json HTTP/1.1" 404
"GET /backup/.codex/auth.json HTTP/1.1" 404
"GET /.claude/.credentials.json HTTP/1.1" 404
"GET /.claude/settings.json HTTP/1.1" 404
"GET /.claude/settings.local.json HTTP/1.1" 404
"GET /.config/claude/credentials.json HTTP
show less
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-21 17:23:50
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
grassau.com
2026-09-21 12:08:32
(3 days ago)
*Port Scan* detected from 34.175.207.140 (ES/Spain/Madrid/Madrid/140.207.175.34.bc.googleusercontent ...
show more
*Port Scan* detected from 34.175.207.140 (ES/Spain/Madrid/Madrid/140.207.175.34.bc.googleusercontent.com).
show less
Port Scan
๐ฎ๐น
VHosting
2026-09-21 09:25:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-21 06:06:23
(3 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
pltcldvlpr
2026-09-21 03:26:52
(3 days ago)
CMS/framework probe: 34.175.207.140 - - [21/Sep/2026:05:26:51 +0200] "GET /www/.claude/credentials.j ...
show more
CMS/framework probe: 34.175.207.140 - - [21/Sep/2026:05:26:51 +0200] "GET /www/.claude/credentials.json HTTP/1.1" 444 0 "-" "crusader-worker/1.0" asn=396982 org="Google LLC" country=ES
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 03:12:32
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 02:56:47
(3 days ago)
[ti-10al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-10al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.175.207.140 - - [21/Sep/2026:04:56:40 +0200] "GET /.codex/auth.json HTTP/1.1" 404 93617 "-" "crusader-worker/1.0"
34.175.207.140 - - [21/Sep/2026:04:56:40 +0200] "GET /.claude/settings.json HTTP/1.1" 404 93622 "-" "crusader-worker/1.0"
34.175.207.140 - - [21/Sep/2026:04:56:40 +0200] "GET /app/.claude/credentials.json HTTP/1.1" 404 93629 "-" "crusader-worker/1.0"
34.175.207.140 - - [21/Sep/2026:04:56:40 +0200] "GET /public/.claude/credentials.json HTTP/1.1" 404 93632 "-" "crusader-worker/1.0"
34.175.207.140 - - [21/Sep/2026:04:56:40 +0200] "GET /files/.codex/auth.json HTTP/1.1" 404 93623 "-" "crusader-worker/1.0"
34.175.207.140 - - [21/Sep/2026:04:56:40 +0200] "GE
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 02:40:34
(3 days ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 22:57:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.175.207.140 (140.207.175.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.207.140 (140.207.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 18:57:24.159926 2026] [security2:error] [pid 9628:tid 9628] [client 34.175.207.140:43246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.21"] [uri "/.git/config"] [unique_id "ahoZ1Is7rBBlXje9MUeh3AAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack