๐บ๐ธ
TPI-Abuse
2026-09-22 05:32:28
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.31.102 (102.31.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.31.102 (102.31.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 01:32:21.977113 2026] [security2:error] [pid 11499:tid 11499] [client 34.84.31.102:38812] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||tyning.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tyning.com"] [uri "/.codex/auth.json.old"] [unique_id "arIS5XQ274dDC-dtDW3TGQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 03:31:37
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.31.102 (102.31.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.31.102 (102.31.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 23:31:29.454305 2026] [security2:error] [pid 25825:tid 25825] [client 34.84.31.102:52006] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pixelspective.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pixelspective.com"] [uri "/.codex/auth.json.bak"] [unique_id "arH2kaGL4IoJbc6G5nZngwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:52:11
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.31.102 (102.31.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.31.102 (102.31.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:52:04.560946 2026] [security2:error] [pid 26593:tid 26608] [client 34.84.31.102:58160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.westfrancia.com.aafm.us|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.westfrancia.com.aafm.us"] [uri "/.codex/auth.json.old"] [unique_id "arHfRGAXGH-Fk57EYdN9-gAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-22 01:42:03
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_u ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_ua, ai_secrets, source_backup. Observed by 1 sensor(s); 100 hits.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 00:25:54
(1 day ago)
34.84.31.102 - - [22/Sep/2026:08:25:53 +0800] "GET /.codex/auth.json HTTP/1.1" 404 149 "-" "crusader ...
show more
34.84.31.102 - - [22/Sep/2026:08:25:53 +0800] "GET /.codex/auth.json HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
34.84.31.102 - - [22/Sep/2026:08:25:53 +0800] "GET /.codex/config.toml HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
34.84.31.102 - - [22/Sep/2026:08:25:53 +0800] "GET /.codex/config.json HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
34.84.31.102 - - [22/Sep/2026:08:25:53 +0800] "GET /.config/codex/auth.json HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
34.84.31.102 - - [22/Sep/2026:08:25:53 +0800] "GET /.codex/auth.json.bak HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 23:10:53
(1 day ago)
Web probing (60 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by C ...
show more
Web probing (60 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:07:05
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.31.102 (102.31.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.31.102 (102.31.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:06:59.326560 2026] [security2:error] [pid 29305:tid 29305] [client 34.84.31.102:40898] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thewhispertwins.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thewhispertwins.com"] [uri "/.codex/auth.json.old"] [unique_id "arG4kxRBWHc6eHYTFdVh1QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:32:53
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.84.31.102 (102.31.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.84.31.102 (102.31.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:32:46.999734 2026] [security2:error] [pid 5000:tid 5000] [client 34.84.31.102:50822] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bahamascruisersguide.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bahamascruisersguide.com"] [uri "/.codex/auth.json.old"] [unique_id "arGwjkGaUA6G4fIFPdjMMwAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 17:00:22
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-21 16:35:18
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ต๐ฑ
TaKeN
2026-09-21 13:24:24
(2 days ago)
Automated Wazuh observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing ...
show more
Automated Wazuh observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 2 matching Wazuh alert(s) between 2026-09-21T15:24:24+02:00 and 2026-09-21T15:24:24+02:00.
show less
Web App Attack
Hacking
๐ซ๐ฎ
YF
2026-09-21 12:30:43
(2 days ago)
404 errors Vulnerability scan
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 11:45:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-09-21 09:08:06
(2 days ago)
Blocked by CSF 13 firewall - Rule: US/United States/102.31.84.34.bc.googleusercontent.com
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 07:54:29
(2 days ago)
Restricted File Access Attempt. Matched phrase ".config/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack