๐บ๐ธ
TPI-Abuse
2026-09-22 06:16:32
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.26.26.244 (244.26.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.26.244 (244.26.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 02:16:23.977242 2026] [security2:error] [pid 13418:tid 13418] [client 34.26.26.244:58846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.puckerbikinis.puckerbikini.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.puckerbikinis.puckerbikini.com"] [uri "/.codex/auth.json.bak"] [unique_id "arIdN7wdGCbODj4PhWcrhQAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-09-22 01:53:02
(22 hours ago)
34.26.26.244 - - [22/Sep/2026:03:53:02 +0200] "-" 408 4017 "-" "-" 34.26.26.244 - - [22/Sep/2026:03: ...
show more
34.26.26.244 - - [22/Sep/2026:03:53:02 +0200] "-" 408 4017 "-" "-" 34.26.26.244 - - [22/Sep/2026:03:53:02 +0200] "-" 408 4018 "-" "-" 34.26.26.244 - - [22/Sep/2026:03:53:02 +0200] "-" 408 4017 "-" "-"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 22:50:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.26.26.244 (244.26.26.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.26.244 (244.26.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:50:46.210845 2026] [security2:error] [pid 17465:tid 17465] [client 34.26.26.244:60978] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||flymarlin.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "flymarlin.com"] [uri "/.codex/auth.json.old"] [unique_id "arG0xj8Nn5L-ZXps2zlhiAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-21 20:24:03
(1 day ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
mnsf
2026-09-21 16:05:19
(1 day ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 15:48:59
(1 day ago)
20 attempts against mh-misbehave-ban on ficus
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 15:30:07
(1 day ago)
[news.tmg.gr] httpd-config-scan: sites=www.news.tmg.gr; logs=/var/log/httpd/domains/news.tmg.gr.log; ...
show more
[news.tmg.gr] httpd-config-scan: sites=www.news.tmg.gr; logs=/var/log/httpd/domains/news.tmg.gr.log; samples=/api/.codex/auth.json | /www/.claude/credentials.json | /.claude/settings.local.json
show less
Hacking
Web App Attack
๐ซ๐ฎ
oh.mg
2026-09-21 07:38:06
(1 day ago)
34.26.26.244 - - [21/Sep/2026:09:38:05 +0200] "GET /backup/.codex/auth.json HTTP/1.1" 403 3087 "-" " ...
show more
34.26.26.244 - - [21/Sep/2026:09:38:05 +0200] "GET /backup/.codex/auth.json HTTP/1.1" 403 3087 "-" "crusader-worker/1.0"
34.26.26.244 - - [21/Sep/2026:09:38:06 +0200] "GET /config/.codex/auth.json HTTP/1.1" 403 3088 "-" "crusader-worker/1.0"
34.26.26.244 - - [21/Sep/2026:09:38:06 +0200] "GET /uploads/.codex/auth.json HTTP/1.1" 403 3087 "-" "crusader-worker/1.0"
34.26.26.244 - - [21/Sep/2026:09:38:06 +0200] "GET /site/.codex/auth.json HTTP/1.1" 403 498 "-" "crusader-worker/1.0"
34.26.26.244 - - [21/Sep/2026:09:38:06 +0200] "GET /api/.codex/auth.json HTTP/1.1" 403 498 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 07:02:08
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 06:18:56
(1 day ago)
[ti-01ov] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail <nam ...
show more
[ti-01ov] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail <name>. Example: 34.26.26.244 - - \[21/Sep/2026:08:18:29 +0200\] "GET /site/.codex/auth.json HTTP/1.1" 404 44810 "-" "crusader-worker/1.0"
34.26.26.244 - - \[21/Sep/2026:08:18:29 +0200\] "GET /data/.claude.json HTTP/1.1" 404 44810 "-" "crusader-worker/1.0"
34.26.26.244 - - \[21/Sep/2026:08:18:29 +0200\] "GET /old/.claude/credentials.json HTTP/1.1" 404 44810 "-" "crusader-worker/1.0"
34.26.26.244 - - \[21/Sep/2026:08:18:29 +0200\] "GET /public/.claude/credentials.json HTTP/1.1" 404 44810 "-" "crusader-worker/1.0"
34.26.26.244 - - \[21/Sep/2026:08:18:29 +0200\] "GET /www/.claude/credentials.json HTTP/1.1" 404 44810 "-" "crusader-worker/1.0"
34.26.26.244 - - \[21/Sep/2026:08:18:29 +0200\] "GET /data/.codex/auth.json HTTP/1.1" 404 44
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 05:08:13
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
Jason Howell
2026-02-09 14:02:40
(7 months ago)
34.26.26.244 - - [09/Feb/2026:08:02:37 -0600] "POST //xmlrpc.php HTTP/1.1" 200 713 "-" "Mozilla/5.0 ...
show more
34.26.26.244 - - [09/Feb/2026:08:02:37 -0600] "POST //xmlrpc.php HTTP/1.1" 200 713 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.26.26.244 - - [09/Feb/2026:08:02:37 -0600] "POST //xmlrpc.php HTTP/1.1" 200 3103 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.26.26.244 - - [09/Feb/2026:08:02:38 -0600] "POST //xmlrpc.php HTTP/1.1" 200 3105 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.26.26.244 - - [09/Feb/2026:08:02:39 -0600] "POST //xmlrpc.php HTTP/1.1" 200 3105 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.26.26.244 - - [09/Feb/2026:08:02:39 -0600] "POST //xmlrpc.php HTTP/1.1" 200 3105 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
...
show less
Web App Attack
๐ณ๐ฑ
Rey
2026-02-09 14:01:02
(7 months ago)
WordPress xmlrpc.php attack [j3epfzl1]
Web App Attack
๐จ๐ฆ
polycoda
2026-02-09 14:01:00
(7 months ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-02-09 14:00:08
(7 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack