Anonymous
2026-09-22 05:22:07
(1 day ago)
[server.techsupportltd.gr] httpd-config-scan: sites=www.motohall.gr; logs=/var/log/httpd/domains/mot ...
show more
[server.techsupportltd.gr] httpd-config-scan: sites=www.motohall.gr; logs=/var/log/httpd/domains/motohall.gr.log; samples=/.codex/config.toml | /.codex/auth.json | /.codex/config.json
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 05:02:03
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.39.87.136 (136.87.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.87.136 (136.87.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 01:01:59.904399 2026] [security2:error] [pid 28598:tid 28635] [client 34.39.87.136:59994] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ethniclivesmatter.aafm.us|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ethniclivesmatter.aafm.us"] [uri "/.codex/auth.json.bak"] [unique_id "arILxzIoLBR16bNjvJKJcAAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-22 02:08:00
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-22 01:05:04
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa01]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-21 23:53:07
(1 day ago)
[22/Sep/2026:02:53:07 +0300] -- 34.39.87.136 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /o ...
show more
[22/Sep/2026:02:53:07 +0300] -- 34.39.87.136 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /old/.claude.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:33:50
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.39.87.136 (136.87.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.87.136 (136.87.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:33:42.809056 2026] [security2:error] [pid 21826:tid 21826] [client 34.39.87.136:41580] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pembrokefinance.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pembrokefinance.com"] [uri "/.codex/auth.json.old"] [unique_id "arG-1kiiN6lrg3z3SrlEqgAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 18:13:57
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-21 17:52:29
(2 days ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
Sonoflet
2026-09-21 15:48:52
(2 days ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 13:30:16
(2 days ago)
20 attempts against mh_ha-misbehave-ban on pf221113
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 11:44:57
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-21 11:15:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-21 11:14:39
(2 days ago)
[Mon Sep 21 13:14:38.761678 2026] [:error] [pid 4077195:tid 4077195] [client 34.39.87.136:34410] Mod ...
show more
[Mon Sep 21 13:14:38.761678 2026] [:error] [pid 4077195:tid 4077195] [client 34.39.87.136:34410] ModSecurity: Warning. Matched "Operator `PmFromFile' with parameter `restricted-files.data' against variable `REQUEST_FILENAME' (Value: `/.claude/.credentials.json' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "131"] [id "930130"] [rev ""] [msg "Restricted File Access Attempt"] [data "Matched Data: .credentials found within REQUEST_FILENAME: /.claude/.credentials.json"] [severity "2"] [ver "OWASP_CRS/4.30.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [uri "/.claude/.credentials.json"] [unique_id "178998927861.882968"] [ref "o9,12v4,26t:utf8toUnicode,t:urlDecodeUni,t:normalizePathWin"]
[Mon Sep 21 13:14:38.763797 2026] [:error] [pid 407
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 03:43:31
(2 days ago)
[livebd] Excessive 404 errors (web scanning): 36 suspicious requests detected by fail2ban jail apach ...
show more
[livebd] Excessive 404 errors (web scanning): 36 suspicious requests detected by fail2ban jail apache-404. Example: 34.39.87.136 - - [21/Sep/2026:05:43:30 +0200] "GET /.codex/config.toml HTTP/1.1" 404 7869 "-" "crusader-worker/1.0"
34.39.87.136 - - [21/Sep/2026:05:43:30 +0200] "GET /.codex/auth.json HTTP/1.1" 404 7869 "-" "crusader-worker/1.0"
34.39.87.136 - - [21/Sep/2026:05:43:30 +0200] "GET /.codex/config.json HTTP/1.1" 404 2065 "-" "crusader-worker/1.0"
34.39.87.136 - - [21/Sep/2026:05:43:30 +0200] "GET /.claude.json HTTP/1.1" 404 2065 "-" "crusader-worker/1.0"
34.39.87.136 - - [21/Sep/2026:05:43:30 +0200] "GET /.claude/credentials.json HTTP/1.1" 404 2065 "-" "crusader-worker/1.0"
34.39.87.136 - - [21/Sep/2026:05:43:30 +0200] "G
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-21 03:04:26
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /www/.claude/credentials.json (+8 more) | 2026-09-21 03:04 UTC
show less
Hacking
Web App Attack