๐ช๐ธ
pipeline.es
2026-09-24 08:59:26
(1 day ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:39:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.182.242.64 (64.242.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.242.64 (64.242.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:39:51.691445 2026] [security2:error] [pid 17282:tid 17282] [client 34.182.242.64:55338] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||cabrynpoodles.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cabrynpoodles.com"] [uri "/.codex/auth.json.bak"] [unique_id "arTh1--KxZnyJZN8KXyKLwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-24 06:42:31
(1 day ago)
excessive HTTP 404 errors
Bad Web Bot
Anonymous
2026-09-24 06:29:12
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 05:15:46
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.182.242.64 (64.242.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.242.64 (64.242.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:15:38.965882 2026] [security2:error] [pid 2606:tid 2606] [client 34.182.242.64:35444] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bodyworkbydallas.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bodyworkbydallas.com"] [uri "/.codex/auth.json.bak"] [unique_id "arSx-nzgJbTquE3oFX-I8gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-24 03:21:28
(2 days ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 01:56:56
(2 days ago)
Web scanning / probing for vulnerable paths | URL: /backup/.claude.json | Evidence: bestincoming.pt ...
show more
Web scanning / probing for vulnerable paths | URL: /backup/.claude.json | Evidence: bestincoming.pt 34.182.242.64 - - [24/Sep/2026:03:56:37 +0200] \"GET /backup/.claude.json HTTP/1.1\" 404 20665 \"-\" \"crusader-worker/1.0\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:51:26
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.182.242.64 (64.242.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.242.64 (64.242.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:51:21.937396 2026] [security2:error] [pid 25789:tid 25789] [client 34.182.242.64:52332] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bervick.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bervick.com"] [uri "/.codex/auth.json.old"] [unique_id "arSCGcA7dctIl8sPoXpSQAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-24 01:20:59
(2 days ago)
20 attempts against mh-misbehave-ban on pf221113
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-24 00:11:19
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-23 17:37:07
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-09-23 10:55:54
(2 days ago)
[livebd] Excessive 404 errors (web scanning): 26 suspicious requests detected by fail2ban jail apach ...
show more
[livebd] Excessive 404 errors (web scanning): 26 suspicious requests detected by fail2ban jail apache-404. Example: 34.182.242.64 - - [23/Sep/2026:12:55:38 +0200] "GET /.codex/config.json HTTP/1.1" 404 7875 "-" "crusader-worker/1.0"
34.182.242.64 - - [23/Sep/2026:12:55:38 +0200] "GET /.codex/config.toml HTTP/1.1" 404 7875 "-" "crusader-worker/1.0"
34.182.242.64 - - [23/Sep/2026:12:55:38 +0200] "GET /.codex/auth.json.bak HTTP/1.1" 404 7875 "-" "crusader-worker/1.0"
34.182.242.64 - - [23/Sep/2026:12:55:38 +0200] "GET /.claude/settings.local.json HTTP/1.1" 404 7875 "-" "crusader-worker/1.0"
34.182.242.64 - - [23/Sep/2026:12:55:38 +0200] "GET /.codex/auth.json~ HTTP/1.1" 404 7875 "-" "crusader-worker/1.0"
34.182.242.64
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 06:01:29
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.182.242.64 (64.242.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.242.64 (64.242.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 02:01:22.390334 2026] [security2:error] [pid 19246:tid 19246] [client 34.182.242.64:44596] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||airwatering.grancanariaholidays.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "airwatering.grancanariaholidays.com"] [uri "/.codex/auth.json.old"] [unique_id "arNrMkokeUgG7joho2OR7QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 05:15:34
(2 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-197)
show less
Hacking
๐ฎ๐น
VHosting
2026-09-23 02:30:08
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack