๐บ๐ธ
TPI-Abuse
2026-09-24 08:49:05
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.178.29.179 (179.29.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.178.29.179 (179.29.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:48:57.402234 2026] [security2:error] [pid 26977:tid 26977] [client 34.178.29.179:35692] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cain2012.org|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cain2012.org"] [uri "/.codex/auth.json.bak"] [unique_id "arTj-TXWoqU4Cr2ZrbZCCAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Feelautom
2026-09-24 07:11:02
(1 day ago)
[FeelAutom Auto-Ban] PathScan: /backup/.config/codex/auth.json (Score: 200)
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-09-24 06:46:54
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-24 06:35:02
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-24 06:27:46
(1 day ago)
[server.tmg.gr] httpd-config-scan: sites=www.bridgesofpneumonology2026.com; logs=/var/log/httpd/doma ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.bridgesofpneumonology2026.com; logs=/var/log/httpd/domains/bridgesofpneumonology2026.com.log; samples=/.claude/settings.json | /site/.codex/auth.json | /.codex/auth.json.save
show less
Hacking
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-24 02:25:01
(1 day ago)
Web App Attack
Anonymous
2026-09-23 19:22:29
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐จ๐ญ
ca
2026-09-23 17:41:37
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
consul.to
2026-09-23 14:15:03
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 13:25:08
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.178.29.179 (179.29.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.178.29.179 (179.29.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 09:25:02.933753 2026] [security2:error] [pid 29163:tid 29195] [client 34.178.29.179:34992] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||appraisalteam.net|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "appraisalteam.net"] [uri "/.codex/auth.json.bak"] [unique_id "arPTLjuPHyO25MfkF3BZ7AAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 12:05:48
(1 day ago)
Restricted File Access Attempt. Matched phrase "credentials.json" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ช๐ธ
robotstxt
2026-09-23 11:51:24
(1 day ago)
34.178.29.179 - - [23/Sep/2026:11:50:43 +0000] "GET /.codex/auth.json~ HTTP/1.1" 403 189 "-" "crusad ...
show more
34.178.29.179 - - [23/Sep/2026:11:50:43 +0000] "GET /.codex/auth.json~ HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="34.178.29.179"
34.178.29.179 - - [23/Sep/2026:11:50:43 +0000] "GET /.codex/auth.json.bak HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="34.178.29.179"
34.178.29.179 - - [23/Sep/2026:11:50:43 +0000] "GET /bak/.codex/auth.json HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="34.178.29.179"
34.178.29.179 - - [23/Sep/2026:11:50:43 +0000] "GET /.claude/.credentials.json HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="34.178.29.179"
34.178.29.179 - - [23/Sep/2026:11:50:43 +0000] "GET /old/.codex/auth.json HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="34.178.29.179"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 07:14:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.178.29.179 (179.29.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.178.29.179 (179.29.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 03:14:44.712128 2026] [security2:error] [pid 27029:tid 27029] [client 34.178.29.179:34312] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alosi.us|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alosi.us"] [uri "/.codex/auth.json.old"] [unique_id "arN8ZBufJT_b3cIhfbbRZwAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 06:39:15
(2 days ago)
Restricted File Access Attempt: AI Coding Assistant Artifact. Matched phrase ".claude/" at REQUEST_F ...
show more
Restricted File Access Attempt: AI Coding Assistant Artifact. Matched phrase ".claude/" at REQUEST_FILENAME. (930140-193)
show less
Hacking
๐ฎ๐น
VHosting
2026-09-23 02:15:06
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack