๐บ๐ธ
TPI-Abuse
2026-09-22 02:56:25
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.65.164.171 (171.164.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.164.171 (171.164.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:56:21.681259 2026] [security2:error] [pid 19174:tid 19174] [client 34.65.164.171:44314] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.warbonnetmusic.tremulant.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.warbonnetmusic.tremulant.com"] [uri "/.codex/auth.json.bak"] [unique_id "arHuVQQtpAkFpVg4vRmo7QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-09-22 01:51:40
(1 day ago)
2026-09-22 @ 03:51:30 (CET) ~ Blocked for trying to access: /.codex/auth.json
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:48:55
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.65.164.171 (171.164.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.164.171 (171.164.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:48:48.330308 2026] [security2:error] [pid 11963:tid 11963] [client 34.65.164.171:48632] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cain2016.org|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cain2016.org"] [uri "/.codex/auth.json.bak"] [unique_id "arGmQAhfCx9T7zhMzwX2SgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 21:26:41
(2 days ago)
30 attempts against mh-misbehave-ban on tin
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 20:37:34
(2 days ago)
20 attempts against mh_ha-misbehave-ban on sedna
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:46:11
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.65.164.171 (171.164.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.164.171 (171.164.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:46:06.253418 2026] [security2:error] [pid 11834:tid 11834] [client 34.65.164.171:47340] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wookheo.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wookheo.com"] [uri "/.codex/auth.json.old"] [unique_id "arGJfhjKNMpr2MtT-HizFAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-21 16:43:14
(2 days ago)
This address swept through a list of pages that do not exist on our site within seconds โ a scanner ...
show more
This address swept through a list of pages that do not exist on our site within seconds โ a scanner working through its wordlist of exploitable paths. Blocked; please check the machine behind it for a scanner or malware. | method: GET | path: /.codex/auth.json (+11 more) | 2026-09-21 16:43 UTC
show less
Port Scan
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 11:13:00
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ญ๐ฐ
้น้น
2026-09-21 07:08:24
(2 days ago)
monitor: on ser162528253480 | port: 8089 | ttl: 127 script: github.com/sefinek/UFW-AbuseIPDB-Report ...
show more
monitor: on ser162528253480 | port: 8089 | ttl: 127 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ซ๐ท
LRNP
2026-09-21 05:19:14
(2 days ago)
stats.lpoujol.fr:443 34.65.164.171 - - [21/Sep/2026:05:19:14 +0000] "GET /.claude/credentials.json H ...
show more
stats.lpoujol.fr:443 34.65.164.171 - - [21/Sep/2026:05:19:14 +0000] "GET /.claude/credentials.json HTTP/1.1" 404 9983 "-" "crusader-worker/1.0"
stats.lpoujol.fr:443 34.65.164.171 - - [21/Sep/2026:05:19:14 +0000] "GET /.claude/settings.json HTTP/1.1" 404 9980 "-" "crusader-worker/1.0"
stats.lpoujol.fr:443 34.65.164.171 - - [21/Sep/2026:05:19:14 +0000] "GET /.codex/auth.json HTTP/1.1" 404 9975 "-" "crusader-worker/1.0"
stats.lpoujol.fr:443 34.65.164.171 - - [21/Sep/2026:05:19:14 +0000] "GET /.claude.json HTTP/1.1" 404 9967 "-" "crusader-worker/1.0"
stats.lpoujol.fr:443 34.65.164.171 - - [21/Sep/2026:05:19:14 +0000] "GET /.codex/config.json HTTP/1.1" 404 9977 "-" "crusader-worker/1.0"
stats.lpoujol.fr:443 34.65.164.171 - - [21/Sep/2026:05:19:14 +0000] "GET /.claude/.credentials.json HTTP/1.1" 404 9984 "-" "crusader-worker/1.0"
stats.lpoujol.fr:443 34.65.164.171 - - [21/Sep/2026:05:19:14 +0000] "GET /.codex/config.toml HTTP/1.1" 404 9977 "-" "crusader-worker/1.0"
stats.lpoujol.fr:443 34.65
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-21 05:02:29
(2 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-21 03:16:28
(2 days ago)
excessive HTTP 404 errors
Bad Web Bot
Anonymous
2026-09-21 02:39:14
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking