๐บ๐ธ
TPI-Abuse
2026-09-22 06:20:29
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.148.39 (39.148.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.148.39 (39.148.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 02:20:25.963000 2026] [security2:error] [pid 23092:tid 23092] [client 34.95.148.39:45376] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ags-ga.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ags-ga.com"] [uri "/.codex/auth.json.old"] [unique_id "arIeKXcgTpDi0Z7igOYO1wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-22 04:16:09
(3 days ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฉ๐ช
rh24
2026-09-22 02:16:09
(3 days ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.95.148.39 (BR/Brazil/39.148.95.34.bc.g ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.95.148.39 (BR/Brazil/39.148.95.34.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 02:10:06
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.148.39 (39.148.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.148.39 (39.148.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:10:00.843488 2026] [security2:error] [pid 22994:tid 22994] [client 34.95.148.39:47202] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.seebeexee.scottwithers.xyz|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.seebeexee.scottwithers.xyz"] [uri "/.codex/auth.json.bak"] [unique_id "arHjeOIRapb7sfRCV6aquAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:17:47
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.95.148.39 (39.148.95.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.148.39 (39.148.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:17:43.120926 2026] [security2:error] [pid 11517:tid 11517] [client 34.95.148.39:37020] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.northgatepark.odessatexas.us|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.northgatepark.odessatexas.us"] [uri "/.codex/auth.json.old"] [unique_id "arHJJ2IF9L8P56AEOntUBQAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-09-21 21:00:41
(3 days ago)
404 errors Vulnerability scan
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 20:52:55
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
webanyone
2026-09-21 20:31:39
(3 days ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 19:43:03
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-21 10:40:22
(4 days ago)
20 attempts against mh-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 10:40:08
(4 days ago)
| [Dangerous/Brazil] Aggressive IP 34.95.148.39 (~30 hits). Type: DoS Defender- Web server 400 error ...
show more
| [Dangerous/Brazil] Aggressive IP 34.95.148.39 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
Alt255
2026-09-21 07:22:09
(4 days ago)
[ti-03ov] Excessive 404 errors (web scanning): 41 suspicious requests detected by fail2ban jail apac ...
show more
[ti-03ov] Excessive 404 errors (web scanning): 41 suspicious requests detected by fail2ban jail apache-404. Example: 34.95.148.39 - - [21/Sep/2026:09:22:06 +0200] "GET /old/.claude.json HTTP/1.1" 404 7826 "-" "crusader-worker/1.0"
34.95.148.39 - - [21/Sep/2026:09:22:06 +0200] "GET /backup/.codex/auth.json HTTP/1.1" 404 7826 "-" "crusader-worker/1.0"
34.95.148.39 - - [21/Sep/2026:09:22:06 +0200] "GET /.claude/.credentials.json HTTP/1.1" 404 7826 "-" "crusader-worker/1.0"
34.95.148.39 - - [21/Sep/2026:09:22:06 +0200] "GET /backup/.claude/credentials.json HTTP/1.1" 404 7826 "-" "crusader-worker/1.0"
34.95.148.39 - - [21/Sep/2026:09:22:06 +0200] "GET /www/.codex/auth.json HTTP/1.1" 404 7826 "-" "crusader-worker/1.0"
34.95.148.39 - - [21/Sep/2026:09:22:06 +0200] "GET /uploads/.codex/au
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 06:07:40
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking