๐บ๐ธ
TPI-Abuse
2026-09-24 03:54:11
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.65.62.203 (203.62.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.62.203 (203.62.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:54:03.376867 2026] [security2:error] [pid 3427633:tid 3427633] [client 34.65.62.203:43802] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blackhillsinfosec.org.mphq.net|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blackhillsinfosec.org.mphq.net"] [uri "/.codex/auth.json.old"] [unique_id "arSe24LF0j_sKCj6TT6SWAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-24 02:12:29
(19 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: /credentials (Match: /credentials)
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-24 01:24:03
(20 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-09-24 00:12:02
(21 hours ago)
categories: DDoS Attack
DDoS Attack
๐ช๐ธ
Francisco Vallejo
2026-09-24 00:11:38
(21 hours ago)
[Thu Sep 24 02:11:37.883964 2026] [core:info] [pid 2070468:tid 126352594282176] [client 34.65.62.203 ...
show more
[Thu Sep 24 02:11:37.883964 2026] [core:info] [pid 2070468:tid 126352594282176] [client 34.65.62.203:41900] AH00128: File does not exist: /var/www/barluna/.codex/config.toml
[Thu Sep 24 02:11:37.886371 2026] [core:info] [pid 2070468:tid 126352342632128] [client 34.65.62.203:41888] AH00128: File does not exist: /var/www/barluna/.codex/auth.json
[Thu Sep 24 02:11:37.887431 2026] [core:info] [pid 2070467:tid 126352619460288] [client 34.65.62.203:41906] AH00128: File does not exist: /var/www/barluna/.codex/config.json
[Thu Sep 24 02:11:37.916096 2026] [core:info] [pid 2070468:tid 126352317454016] [client 34.65.62.203:41900] AH00128: File does not exist: /var/www/barluna/.config/codex/auth.json
[Thu Sep 24 02:11:37.917974 2026] [core:info] [pid 2070468:tid 126352602674880] [client 34.65.62.203:41888] AH00128: File does not exist: /var/www/barluna/.codex/auth.json.bak
...
show less
Brute-Force
SSH
๐ซ๐ท
masterguru
2026-09-24 00:11:13
(21 hours ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:59:03
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.65.62.203 (203.62.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.62.203 (203.62.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:58:58.210046 2026] [security2:error] [pid 31822:tid 31822] [client 34.65.62.203:34318] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||azbrooks.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "azbrooks.com"] [uri "/.codex/auth.json.bak"] [unique_id "arRLonT-E6KK1SxDvPjvvgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-23 18:20:48
(1 day ago)
[WedSep2320:20:40.8394832026][security2:error][pid999768:tid1000002][client34.65.62.203:0]ModSecurit ...
show more
[WedSep2320:20:40.8394832026][security2:error][pid999768:tid1000002][client34.65.62.203:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"[a-z0-9]~\$\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1158\"][id\"390581\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-DataLeakage-attempttoaccessbackupfile\(disablethisruleifyourequireaccesstofilesthatendwithatilde\)\"][severity\"CRITICAL\"][hostname\"autodiscover.gsdsagl.ch\"][uri\"/.codex/auth.json~\"][unique_id\"arQYeMTiZiNkPSzt8sIUUwAAAIA\"]
show less
Hacking
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-23 17:33:31
(1 day ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.65.62.2 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.65.62.203 (CH/Switzerland/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.65.62.203 (CH/Switzerland/203.62.65.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ฑ๐น
NotACaptcha
2026-09-23 16:16:10
(1 day ago)
webserver:443 [23/Sep/2026] "GET /tmp/.codex/auth.json HTTP/1.1" 302 467 "-" "crusader-worker/1.0"
...
show more
webserver:443 [23/Sep/2026] "GET /tmp/.codex/auth.json HTTP/1.1" 302 467 "-" "crusader-worker/1.0"
webserver:443 [23/Sep/2026] "GET /.codex/config.toml HTTP/1.1" 302 5845 "-" "crusader-worker/1.0"
webserver:443 [23/Sep/2026] "GET /.codex/auth.json.bak HTTP/1.1" 302 5849 "-" "crusader-worker/1.0"
webserver:443 [23/Sep/2026] "GET /bak/.claude/credentials.json HTTP/1.1" 302 5865 "-" "crusader-worker/1.0"
webserver:443 [23/Sep/2026] "GET /data/.claude.json HTTP/1.1" 302 5843 "-" "crusader-worker/1.0"
webserver:443 [23/Sep/2026] "GET /uploads/.codex/auth.json HTTP/1.1" 302 5857 "-" "crusader-worker/1.0"
webserver:443 [23/Sep/2026] "GET /root/.codex/auth.json HTTP/1.1" 302 5851 "-" "crusader-worker/1.0"
webserver:443 [23/Sep/2026] "GET /htdocs/.codex/auth.json HTTP/1.1" 302 5855 "-" "crusader-worker/1.0"
webserver:443 [23/Sep/2026] "GET /backup/.config/codex/auth.json HTTP/1.1" 302 5869 "-" "crusader-worker/1.0"
webserver:443 [23/Sep/2026] "GET /public/.codex/auth.json HTTP/1.1" 30...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-09-23 07:43:29
(1 day ago)
961 requests with url.path */auth.json
342 requests with url.path *credentials.json
156 requests ...
show more
961 requests with url.path */auth.json
342 requests with url.path *credentials.json
156 requests with url.path *.config/*
show less
Brute-Force
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-23 06:38:36
(1 day ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 05:08:56
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.65.62.203 (203.62.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.62.203 (203.62.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 01:08:51.914813 2026] [security2:error] [pid 23853:tid 23853] [client 34.65.62.203:60508] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||afscmelocal2794.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "afscmelocal2794.com"] [uri "/.codex/auth.json.bak"] [unique_id "arNe4_UUD6JuEGso5fRXPwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 04:35:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.65.62.203 (203.62.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.62.203 (203.62.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 00:35:52.699448 2026] [security2:error] [pid 31260:tid 31260] [client 34.65.62.203:35726] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||advantstudio.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "advantstudio.com"] [uri "/.codex/auth.json.old"] [unique_id "arNXKDtt_shbttA-_ZG6KwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 00:48:23
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.65.62.203 (203.62.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.65.62.203 (203.62.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:48:18.940180 2026] [security2:error] [pid 381:tid 381] [client 34.65.62.203:45020] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aavondalervstorage.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aavondalervstorage.com"] [uri "/.codex/auth.json.bak"] [unique_id "arMh0rLdxav4K7uiAEXolwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack