πΊπΈ
TPI-Abuse
2026-09-24 07:23:27
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.22.108.100 (100.108.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.108.100 (100.108.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:23:19.576029 2026] [security2:error] [pid 22705:tid 22705] [client 34.22.108.100:57162] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||burningdownthevillger.com.tremulant.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "burningdownthevillger.com.tremulant.com"] [uri "/.codex/auth.json.bak"] [unique_id "arTP524j4hjxTmsNepbS-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 03:04:26
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.22.108.100 (100.108.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.108.100 (100.108.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:04:18.334768 2026] [security2:error] [pid 8740:tid 8740] [client 34.22.108.100:59908] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||billiardlifetapleague.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "billiardlifetapleague.com"] [uri "/.codex/auth.json.old"] [unique_id "arSTMndS7eN6xsA0oVHWXAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-09-23 17:58:04
(2 weeks ago)
[WedSep2319:57:57.3973982026][security2:error][pid2524032:tid2524044][client34.22.108.100:0]ModSecur ...
show more
[WedSep2319:57:57.3973982026][security2:error][pid2524032:tid2524044][client34.22.108.100:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"autodiscover.buletti-panettoni.ch\"][uri\"/.codex/auth.json.bak\"][unique_id\"arQTJaqEzJtiBDUpnCOeBQAAAUE\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 17:51:29
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.22.108.100 (100.108.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.108.100 (100.108.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:51:25.259650 2026] [security2:error] [pid 8668:tid 8668] [client 34.22.108.100:37638] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.bayarealangarts.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.bayarealangarts.com"] [uri "/.codex/auth.json.bak"] [unique_id "arQRnaJWSQefbaIKWWnNxgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 16:51:10
(2 weeks ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-23 10:17:20
(2 weeks ago)
fail2ban: Sensitive web probes detected
Web App Attack
π³π±
Alt255
2026-09-23 10:16:31
(2 weeks ago)
[livebd] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apach ...
show more
[livebd] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.22.108.100 - - [23/Sep/2026:12:16:19 +0200] "GET /old/.codex/auth.json HTTP/1.1" 404 7789 "-" "crusader-worker/1.0"
34.22.108.100 - - [23/Sep/2026:12:16:19 +0200] "GET /.claude/.credentials.json HTTP/1.1" 404 7789 "-" "crusader-worker/1.0"
34.22.108.100 - - [23/Sep/2026:12:16:19 +0200] "GET /backup/.codex/auth.json HTTP/1.1" 404 7789 "-" "crusader-worker/1.0"
34.22.108.100 - - [23/Sep/2026:12:16:19 +0200] "GET /.claude.json HTTP/1.1" 404 7789 "-" "crusader-worker/1.0"
34.22.108.100 - - [23/Sep/2026:12:16:19 +0200] "GET /old/.claude.json HTTP/1.1" 404 7789 "-" "crusader-worker/1.0"
34.22.108.100 - - [23/Sep/2026:12:16:19 +0200] "GET /bak/.codex/a
...
show less
Bad Web Bot
Web App Attack
π©πͺ
Manuel Braeuer
2026-09-23 10:13:40
(2 weeks ago)
34.22.108.100 - - [23/Sep/2026:12:13:40 +0200] "GET /var/www/.codex/auth.json HTTP/1.1" 403 5531 "-" ...
show more
34.22.108.100 - - [23/Sep/2026:12:13:40 +0200] "GET /var/www/.codex/auth.json HTTP/1.1" 403 5531 "-" "crusader-worker/1.0"
34.22.108.100 - - [23/Sep/2026:12:13:40 +0200] "GET /.claude/settings.json HTTP/1.1" 403 5531 "-" "crusader-worker/1.0"
34.22.108.100 - - [23/Sep/2026:12:13:40 +0200] "GET /old/.claude/credentials.json HTTP/1.1" 403 5531 "-" "crusader-worker/1.0"
34.22.108.100 - - [23/Sep/2026:12:13:40 +0200] "GET /web/.codex/auth.json HTTP/1.1" 403 5531 "-" "crusader-worker/1.0"
34.22.108.100 - - [23/Sep/2026:12:13:40 +0200] "GET /site/.codex/auth.json HTTP/1.1" 403 5531 "-" "crusader-worker/1.0"
...
show less
Web App Attack
π¬π§
consul.to
2026-09-23 09:25:22
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-23 05:12:25
(2 weeks ago)
[23/Sep/2026:08:12:25 +0300] -- 34.22.108.100 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[23/Sep/2026:08:12:25 +0300] -- 34.22.108.100 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /html/.claude.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 02:32:41
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.22.108.100 (100.108.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.108.100 (100.108.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:32:33.369039 2026] [security2:error] [pid 2006:tid 2006] [client 34.22.108.100:34798] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||addisonchiropracticcenter.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "addisonchiropracticcenter.com"] [uri "/.codex/auth.json.old"] [unique_id "arM6QQrCCS1MQNfVCgRnmgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
naveeddaros
2026-09-22 23:49:26
(2 weeks ago)
HTTP Flood DDoS attack detected
Brute-Force
Bad Web Bot
π©πͺ
Hugopvigo
2026-09-22 09:31:44
(2 weeks ago)
34.22.108.100 - - [22/Sep/2026:11:31:41 +0200] "GET /old/.claude/credentials.json HTTP/1.1" 404 9732 ...
show more
34.22.108.100 - - [22/Sep/2026:11:31:41 +0200] "GET /old/.claude/credentials.json HTTP/1.1" 404 97323 "-" "crusader-worker/1.0"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
πΊπΈ
TPI-Abuse
2026-09-22 08:48:16
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.22.108.100 (100.108.22.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.108.100 (100.108.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:48:09.103440 2026] [security2:error] [pid 28492:tid 28716] [client 34.22.108.100:40280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leaderoftheopposition.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leaderoftheopposition.com"] [uri "/.codex/auth.json.old"] [unique_id "arJAybyK5sHcBYvCAt3e-QAAAlQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-22 07:51:48
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking