๐บ๐ธ
TPI-Abuse
2026-09-24 09:03:15
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.22.90.164 (164.90.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.90.164 (164.90.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:03:09.857271 2026] [security2:error] [pid 16119:tid 16119] [client 34.22.90.164:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||camera.365soft.top|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "camera.365soft.top"] [uri "/.codex/auth.json.old"] [unique_id "arTnTS-lUvM4ptA7y5DAhAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 08:58:40
(5 days ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:38:01
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.22.90.164 (164.90.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.90.164 (164.90.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:37:53.924452 2026] [security2:error] [pid 29597:tid 29614] [client 34.22.90.164:44492] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boracayboats.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boracayboats.com"] [uri "/.codex/auth.json.old"] [unique_id "arS3MQyZQbegvhr1OJAOdQAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:05:34
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.22.90.164 (164.90.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.90.164 (164.90.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:05:27.966032 2026] [security2:error] [pid 4800:tid 4800] [client 34.22.90.164:35844] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boatmoldremover.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boatmoldremover.com"] [uri "/.codex/auth.json.bak"] [unique_id "arSvl8FRm7HxnJHVM052pgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 01:31:21
(5 days ago)
631 requests with url.path */auth.json
207 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-23 22:50:57
(5 days ago)
90 attempts against mh-misbehave-ban on tin
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 16:42:41
(5 days ago)
Web scanning / probing for vulnerable paths | URL: /.codex/auth.json | Evidence: attitude2travel.com ...
show more
Web scanning / probing for vulnerable paths | URL: /.codex/auth.json | Evidence: attitude2travel.com 34.22.90.164 - - [23/Sep/2026:18:41:25 +0200] \"GET /.codex/auth.json HTTP/1.1\" 404 20983 \"-\" \"crusader-worker/1.0\" GEOIP_COUNTRY_CODE=KR | ASN: GOOGLE-CLOUD-PLATFORM | Country: KR
show less
Port Scan
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 14:39:19
(5 days ago)
excessive HTTP 404 errors
Bad Web Bot
๐ซ๐ท
vtchost.com
2026-09-23 14:19:10
(5 days ago)
forbidden http request, scanning for weaknesses
...
Web App Attack
Anonymous
2026-09-23 13:42:58
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
โจ
2026-09-23 03:44:09
(6 days ago)
Domain : admin.lake9.co.uk
Rule : config
2026-09-23 03:42:05 ***hidden-privacy*** GET /.codex/config ...
show more
Domain : admin.lake9.co.uk
Rule : config
2026-09-23 03:42:05 ***hidden-privacy*** GET /.codex/config.toml - 443 - 34.22.90.164 HTTP/1.1 crusader-worker/1.0 - admin.lake9.co.uk 404 0 2 1550 107 836 - -
show less
Hacking
SQL Injection
๐ซ๐ท
โจ
2026-09-23 02:16:10
(6 days ago)
Domain : acrelifts.net
Rule : hack
2026-09-23 02:13:54 W3SVC29 PLESK76 217.194.212.111 GET /.codex/a ...
show more
Domain : acrelifts.net
Rule : hack
2026-09-23 02:13:54 W3SVC29 PLESK76 217.194.212.111 GET /.codex/auth.json.bak - 443 - 34.22.90.164 HTTP/1.1 crusader-worker/1.0 - - acrelifts.net 404 0 64 0 105 5077 - -
show less
Hacking
SQL Injection
Brute-Force
๐ฌ๐ง
consul.to
2026-09-23 01:35:23
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-09-23 00:05:36
(6 days ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:57:32
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.22.90.164 (164.90.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.22.90.164 (164.90.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:57:25.348051 2026] [security2:error] [pid 810:tid 810] [client 34.22.90.164:34324] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||36quant.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "36quant.com"] [uri "/.codex/auth.json.old"] [unique_id "arKXVSpWO3TzqM_x4jUu3QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack