๐ซ๐ท
SpaceHost-Server
2026-09-22 22:24:16
(3 days ago)
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-09-22 06:39:20
(4 days ago)
130 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
๐ฌ๐ง
gws-hostmaster
2026-09-22 02:15:18
(4 days ago)
ModSecurity OWASP CRS (Anomaly Score: 15): Attempt to access a backup or working file;Restricted Fil ...
show more
ModSecurity OWASP CRS (Anomaly Score: 15): Attempt to access a backup or working file;Restricted File Access Attempt;Restricted File Access Attempt: AI Coding Assistant Artifact;URL file extension is restricted by policy;
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:10:41
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.187.113.165 (165.113.187.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.187.113.165 (165.113.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:10:34.463873 2026] [security2:error] [pid 28405:tid 28405] [client 34.187.113.165:39880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.smarthome.varnadorefamily.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.smarthome.varnadorefamily.com"] [uri "/.codex/auth.json.bak"] [unique_id "arHVipwe82t5a_PSAEd2aAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Philister11
2026-09-22 00:25:17
(4 days ago)
CrowdSec: crowdsecurity/http-probing (NL/AS396982)
Web App Attack
Hacking
๐ซ๐ท
SpaceHost-Server
2026-09-21 22:22:48
(4 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:28:42
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.187.113.165 (165.113.187.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.187.113.165 (165.113.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:28:38.252678 2026] [security2:error] [pid 16190:tid 16190] [client 34.187.113.165:53628] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||sekelconsulting.com.z-mgmt.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sekelconsulting.com.z-mgmt.com"] [uri "/.codex/auth.json.bak"] [unique_id "arGTdt7ogyMe-75NdAj7cgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-09-21 14:52:36
(5 days ago)
2026/09/21 14:52:35 [error] 1144018#1144018: *21828568 access forbidden by rule, client: 34.187.113. ...
show more
2026/09/21 14:52:35 [error] 1144018#1144018: *21828568 access forbidden by rule, client: 34.187.113.165, server: binixo.com.ua, request: "GET /.codex/config.toml HTTP/1.1", host: "binixo.com.ua"
2026/09/21 14:52:35 [error] 1144021#1144021: *21828569 access forbidden by rule, client: 34.187.113.165, server: binixo.com.ua, request: "GET /backup/.claude.json HTTP/1.1", host: "binixo.com.ua"
2026/09/21 14:52:35 [error] 1144017#1144017: *21828571 access forbidden by rule, client: 34.187.113.165, server: binixo.com.ua, request: "GET /.claude/.credentials.json HTTP/1.1", host: "binixo.com.ua"
...
show less
Web App Attack
Anonymous
2026-09-21 09:52:53
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-21 09:37:59
(5 days ago)
34.187.113.165 - - [21/Sep/2026:17:37:59 +0800] "GET /backup/.claude/credentials.json HTTP/1.1" 404 ...
show more
34.187.113.165 - - [21/Sep/2026:17:37:59 +0800] "GET /backup/.claude/credentials.json HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.187.113.165 - - [21/Sep/2026:17:37:59 +0800] "GET /.claude/.credentials.json HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.187.113.165 - - [21/Sep/2026:17:37:59 +0800] "GET /old/.claude/credentials.json HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.187.113.165 - - [21/Sep/2026:17:37:59 +0800] "GET /.claude/credentials.json HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.187.113.165 - - [21/Sep/2026:17:37:59 +0800] "GET /opt/.codex/auth.json HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.187.113.165 - - [21/Sep/2026:17:37:59 +0800] "GET /bak/.codex/auth.json HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.187.113.165 - - [21/Sep/2026:17:37:59 +0800] "GET /root/.codex/auth.json HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.187.113.165 - - [21/Sep/2026:17:37:59 +0800] "GET /old/.codex/auth.json HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.187.113.165 - -
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-21 08:38:45
(5 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.codex/config.toml (+14 more) | 2026-09-21 08:38 UTC
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 06:02:26
(5 days ago)
Web attack/malicious scanning detected
Web App Attack