๐บ๐ธ
mnsf
2026-09-22 07:05:15
(4 hours ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 04:15:29
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.94.189.211 (211.189.94.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.94.189.211 (211.189.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:15:26.351987 2026] [security2:error] [pid 27552:tid 27552] [client 34.94.189.211:51060] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||southernreader.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "southernreader.com"] [uri "/.codex/auth.json.bak"] [unique_id "arIA3tsU_nlxQD-_Xm5EoQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 03:38:24
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.94.189.211 (211.189.94.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.94.189.211 (211.189.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 23:38:17.719588 2026] [security2:error] [pid 24746:tid 24746] [client 34.94.189.211:59208] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.itimetable21.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.itimetable21.com"] [uri "/.codex/auth.json.bak"] [unique_id "arH4KTvKDunvTQu3a9i1WgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:41:59
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.94.189.211 (211.189.94.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.94.189.211 (211.189.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:41:56.073526 2026] [security2:error] [pid 6464:tid 6464] [client 34.94.189.211:38182] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||energycapitalinvestments.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "energycapitalinvestments.com"] [uri "/.codex/auth.json.old"] [unique_id "arHAxOqonOJ5ycMj4f1N3AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 23:14:47
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 21:52:37
(13 hours ago)
34.94.189.211 - - [21/Sep/2026:21:51:35 +0000] "GET /files/.codex/auth.json HTTP/2.0" 403 47668 "-" ...
show more
34.94.189.211 - - [21/Sep/2026:21:51:35 +0000] "GET /files/.codex/auth.json HTTP/2.0" 403 47668 "-" "crusader-worker/1.0" "34.94.189.211" edge="172.70.206.152"
34.94.189.211 - - [21/Sep/2026:21:51:35 +0000] "GET /.claude.json HTTP/2.0" 403 47668 "-" "crusader-worker/1.0" "34.94.189.211" edge="104.23.251.35"
34.94.189.211 - - [21/Sep/2026:21:51:35 +0000] "GET /.codex/config.toml HTTP/2.0" 403 47668 "-" "crusader-worker/1.0" "34.94.189.211" edge="172.64.217.114"
34.94.189.211 - - [21/Sep/2026:21:51:35 +0000] "GET /.codex/auth.json.txt HTTP/2.0" 403 47668 "-" "crusader-worker/1.0" "34.94.189.211" edge="104.23.251.34"
34.94.189.211 - - [21/Sep/2026:21:51:35 +0000] "GET /backup/.config/codex/auth.json HTTP/2.0" 403 47668 "-" "crusader-worker/1.0" "34.94.189.211" edge="104.23.251.35"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:01:49
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.94.189.211 (211.189.94.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.94.189.211 (211.189.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:01:43.111792 2026] [security2:error] [pid 18493:tid 18493] [client 34.94.189.211:46314] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thepinman.org|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thepinman.org"] [uri "/.codex/auth.json.old"] [unique_id "arGNJ5UFpksa3vYrvH2GfQAAAHE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 18:50:56
(16 hours ago)
Web application attack detected.
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-21 16:15:08
(18 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-21 15:30:53
(19 hours ago)
20 attempts against mh_ha-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 06:05:42
(1 day ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 05:50:58
(1 day ago)
20 attempts against mh-misbehave-ban on bud
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 05:05:09
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ง๐ฌ
Stoyko Stoykov
2026-09-21 02:49:51
(1 day ago)
34.94.189.211 - - [21/Sep/2026:05:49:51 +0300] "GET /config/.codex/auth.json HTTP/1.1" 404 0 "-" "cr ...
show more
34.94.189.211 - - [21/Sep/2026:05:49:51 +0300] "GET /config/.codex/auth.json HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-21 02:41:04
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack