๐ช๐ธ
pipeline.es
2026-09-24 08:59:24
(1 day ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 07:34:22
(1 day ago)
555 limiting connections by zone (13m59s)
DDoS Attack
๐ฌ๐ง
consul.to
2026-09-24 07:12:52
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:29:55
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.90.213.141 (141.213.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.213.141 (141.213.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:29:50.528418 2026] [security2:error] [pid 19424:tid 19424] [client 34.90.213.141:58956] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||book-arts.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "book-arts.com"] [uri "/.codex/auth.json.bak"] [unique_id "arS1Ti9I36NvrDkKlsn-OQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 01:52:54
(2 days ago)
Web scanning / probing for vulnerable paths | URL: /.claude/credentials.json | Evidence: www.bestfly ...
show more
Web scanning / probing for vulnerable paths | URL: /.claude/credentials.json | Evidence: www.bestflycaboverde.com 34.90.213.141 - - [24/Sep/2026:03:52:19 +0200] \"GET /.claude/credentials.json HTTP/1.1\" 404 21904 \"-\" \"crusader-worker/1.0\" GEOIP_COUNTRY_CODE=NL | ASN: GOOGLE-CLOUD-PLATFORM | Country: NL
show less
Port Scan
Web App Attack
๐ซ๐ท
masterguru
2026-09-24 00:13:29
(2 days ago)
Restricted File Access Attempt. Matched phrase "credentials.json" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:47:43
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.90.213.141 (141.213.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.213.141 (141.213.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:47:38.369130 2026] [security2:error] [pid 28192:tid 28192] [client 34.90.213.141:43452] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.anatolyaleksin.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.anatolyaleksin.com"] [uri "/.codex/auth.json.old"] [unique_id "arQQugSDMR4v29mNOBwQ-wAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 14:07:07
(2 days ago)
Automated web scanner. Requested suspicious paths: /.codex/auth.json.txt | /.codex/config.json | /.c ...
show more
Automated web scanner. Requested suspicious paths: /.codex/auth.json.txt | /.codex/config.json | /.claude/settings.local.json | /data/.claude.json | /backup/.claude.json | /public/.codex/auth.json | /.config/claude/credentials.json | /site/.codex/auth.json | /config/.codex/auth.json | /www/.claude/credentials.json | /home/.codex/auth.json | /old/.codex/auth.json | /tmp/.codex/auth.json | /web/.codex/auth.json | /.codex/auth.json.save | /old/.config/codex/auth.json | /.codex/config.toml | /.claude/.credentials.json | /data/.codex/auth.json | /bak. UTC: 2026-09-23 14:00:33.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 12:03:04
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.90.213.141 (141.213.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.213.141 (141.213.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 08:02:57.386647 2026] [security2:error] [pid 9904:tid 10054] [client 34.90.213.141:49848] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aplinet.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aplinet.com"] [uri "/.codex/auth.json.old"] [unique_id "arO_8Xe_De7TfO2lQ5uYJwAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-09-23 08:24:02
(2 days ago)
categories: DDoS Attack
DDoS Attack
๐ณ๐ฑ
Savvii
2026-09-23 07:43:41
(2 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 06:49:35
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.90.213.141 (141.213.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.213.141 (141.213.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 02:49:28.987909 2026] [security2:error] [pid 1917574:tid 1917574] [client 34.90.213.141:39280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alexlacruz.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alexlacruz.com"] [uri "/.codex/auth.json.bak"] [unique_id "arN2eMzs5hlMLCv46VYZWQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-23 05:30:06
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-23 04:51:46
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 21:08:25
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.90.213.141 (141.213.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.90.213.141 (141.213.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:08:18.720777 2026] [security2:error] [pid 10951:tid 10951] [client 34.90.213.141:42642] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||80corvette.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "80corvette.com"] [uri "/.codex/auth.json.old"] [unique_id "arLuQkku9n58TCjZOVlarAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack