๐ณ๐ฑ
i-turnradio.nl
2026-09-24 09:04:24
(1 day ago)
2026-09-24 @ 11:04:10 (CET) ~ Blocked for trying to access: /home/.codex/auth.json
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 07:39:59
(1 day ago)
944 requests with url.path */auth.json
372 requests with url.path *credentials.json
162 requests ...
show more
944 requests with url.path */auth.json
372 requests with url.path *credentials.json
162 requests with url.path *.config/*
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
svr
2026-09-24 07:34:29
(1 day ago)
HC-Flood Web Scanner
Web App Attack
๐บ๐ธ
kosada.com
2026-09-24 06:39:56
(1 day ago)
Repeated exploit attempts, for example: /backup/.config/codex/auth.json /backup/ (HTTP/1.1 port 443)
Web App Attack
๐บ๐ธ
JonathanYoung2161
2026-09-24 06:26:58
(1 day ago)
brightideasdesign.store 34.72.44.209 - - [24/Sep/2026:01:26:56 -0500] "GET /.claude/credentials.json ...
show more
brightideasdesign.store 34.72.44.209 - - [24/Sep/2026:01:26:56 -0500] "GET /.claude/credentials.json HTTP/2.0" 403 3481 "-" "crusader-worker/1.0"
brightideasdesign.store 34.72.44.209 - - [24/Sep/2026:01:26:56 -0500] "GET /backup/.claude/credentials.json HTTP/2.0" 403 3481 "-" "crusader-worker/1.0"
brightideasdesign.store 34.72.44.209 - - [24/Sep/2026:01:26:56 -0500] "GET /.config/claude/credentials.json HTTP/2.0" 403 3481 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-24 05:39:17
(1 day ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:01:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.72.44.209 (209.44.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.72.44.209 (209.44.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:01:30.170400 2026] [security2:error] [pid 29815:tid 29815] [client 34.72.44.209:53930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bnaior.joyfulservice.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bnaior.joyfulservice.com"] [uri "/.codex/auth.json.bak"] [unique_id "arSuqpTKKm_3GdvJ4wanrQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-24 03:15:58
(1 day ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:06:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.72.44.209 (209.44.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.72.44.209 (209.44.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:06:36.784737 2026] [security2:error] [pid 17170:tid 17170] [client 34.72.44.209:51636] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||billfried.net|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "billfried.net"] [uri "/.codex/auth.json.old"] [unique_id "arSTvKwmck9LVxK6oRTEKQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:50:34
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.72.44.209 (209.44.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.72.44.209 (209.44.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:50:31.709776 2026] [security2:error] [pid 23819:tid 23819] [client 34.72.44.209:34908] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||berlatinc.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "berlatinc.com"] [uri "/.codex/auth.json.bak"] [unique_id "arSB50j95QevwDv7iOuVagAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-09-24 01:45:02
(1 day ago)
categories: DDoS Attack
DDoS Attack
๐ซ๐ฎ
albionfreemarket.com
2026-09-23 09:47:24
(2 days ago)
2026/09/23 09:47:22 [error] 600#600: *110899 limiting requests, excess: 20.090 by zone "limit_per_se ...
show more
2026/09/23 09:47:22 [error] 600#600: *110899 limiting requests, excess: 20.090 by zone "limit_per_sec", client: 34.72.44.209, server: api.albionfreemarket.com, request: "GET /srv/.codex/auth.json HTTP/2.0", host: "api.albionfreemarket.com"
2026/09/23 09:47:22 [error] 600#600: *110911 limiting requests, excess: 20.010 by zone "limit_per_sec", client: 34.72.44.209, server: api.albionfreemarket.com, request: "GET /.claude/settings.local.json HTTP/2.0", host: "api.albionfreemarket.com"
2026/09/23 09:47:22 [error] 600#600: *110910 limiting requests, excess: 20.770 by zone "limit_per_sec", client: 34.72.44.209, server: api.albionfreemarket.com, request: "GET /opt/.codex/auth.json HTTP/2.0", host: "api.albionfreemarket.com"
2026/09/23 09:47:22 [error] 600#600: *110912 limiting requests, excess: 20.670 by zone "limit_per_sec", client: 34.72.44.209, server: api.albionfreemarket.com, request: "GET /backup/.codex/auth.json HTTP/2.0", host: "api.albionfreemarket.com"
2026/09/23 09:47:22 [error] 60
...
show less
Bad Web Bot
๐บ๐ธ
mnsf
2026-09-23 09:05:37
(2 days ago)
Too many Status 40X (11)
Request Overload (102)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-23 08:45:05
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-23 05:27:41
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking