๐ซ๐ท
masterguru
2026-09-24 09:01:44
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".config/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ซ๐ท
IRISIO
2026-09-24 06:32:04
(9 hours ago)
scans/SQL injection/spam posts : 150 queries
Web App Attack
SQL Injection
๐บ๐ธ
Jakub Sikora
2026-09-24 06:00:09
(9 hours ago)
PHP webshell scanner detected by honeytrap. Threat score: 60, total requests: 2. Probed paths: /back ...
show more
PHP webshell scanner detected by honeytrap. Threat score: 60, total requests: 2. Probed paths: /backup/.codex/auth.json, /backup/.config/codex/auth.json. Triggered honeypots: tarpit_download.
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:20:45
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.87.198.212 (212.198.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.198.212 (212.198.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:20:38.287213 2026] [security2:error] [pid 19467:tid 19467] [client 34.87.198.212:53432] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bolivarbulletintimes.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bolivarbulletintimes.com"] [uri "/.codex/auth.json.bak"] [unique_id "arSzJtFQS7xivZyJ1xysmQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
ciccio diddo
2026-09-24 03:52:47
(11 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-24 02:33:32
(13 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.config/codex/auth.json (+12 more) | 2026-09-24 02:33 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:39:02
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.87.198.212 (212.198.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.198.212 (212.198.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:38:56.370583 2026] [security2:error] [pid 31234:tid 31234] [client 34.87.198.212:56038] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bbernal.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bbernal.com"] [uri "/.codex/auth.json.bak"] [unique_id "arRxIAH3LQeq2N_4cVfOqgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:15:54
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.87.198.212 (212.198.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.198.212 (212.198.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:15:47.468754 2026] [security2:error] [pid 23143:tid 23160] [client 34.87.198.212:51554] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arthansl.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arthansl.com"] [uri "/.codex/auth.json.bak"] [unique_id "arPtI6uFkkkwiTpzmjssyQAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 08:40:23
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.87.198.212 (212.198.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.87.198.212 (212.198.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 04:40:19.912995 2026] [security2:error] [pid 32147:tid 32147] [client 34.87.198.212:47330] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||angelpalomino.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "angelpalomino.com"] [uri "/.codex/auth.json.bak"] [unique_id "arOQczJdOwJpR9ujNmJzmgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-09-23 06:45:01
(1 day ago)
categories: DDoS Attack
DDoS Attack
Anonymous
2026-09-23 05:06:08
(1 day ago)
Trying to access config files
Web App Attack
๐ต๐ฑ
lns.bz
2026-09-23 01:01:02
(1 day ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 10:05:23
(2 days ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
Anonymous
2026-09-22 09:36:30
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-22 08:55:09
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack