๐ง๐ท
radardatelecom
2026-09-25 22:26:02
(1 week ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-25 22:01:18
(1 week ago)
Auto-ban: 300 malicious requests on 2026-09-24 (e.g., env/backup probes, brute-force, or error burst ...
show more
Auto-ban: 300 malicious requests on 2026-09-24 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
SpaceHost-Server
2026-09-24 22:24:50
(1 week ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:36:42
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:36:38.056647 2026] [security2:error] [pid 17482:tid 17573] [client 35.189.34.26:50150] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||buyused-jomega.jomega.org|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "buyused-jomega.jomega.org"] [uri "/.codex/auth.json.old"] [unique_id "arTTBlAu69YWKiAjxsYdGQAAAdU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-24 07:22:04
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:41:08
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:41:02.804105 2026] [security2:error] [pid 9536:tid 9626] [client 35.189.34.26:54934] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bronnimann.org|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bronnimann.org"] [uri "/.codex/auth.json.old"] [unique_id "arTF_i5NSpcc2uzNSqYImgAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:54:59
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:54:53.452915 2026] [security2:error] [pid 15128:tid 15128] [client 35.189.34.26:55170] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bluestarplumberseasttexas.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bluestarplumberseasttexas.com"] [uri "/.codex/auth.json.old"] [unique_id "arStHUaopQ8kYLrV-v2t3gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2026-09-24 04:31:04
(1 week ago)
tcp/80; /config.json exposure probe: "GET /.codex/config.json" @ 2026-09-24T04:27:39Z
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-24 03:03:16
(1 week ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 02:48:33
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:48:28.055081 2026] [security2:error] [pid 9027:tid 9095] [client 35.189.34.26:57282] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||biblewriter.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "biblewriter.com"] [uri "/.codex/auth.json.old"] [unique_id "arSPfN8RmUkVfjF0XRolBQAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-09-24 01:24:36
(1 week ago)
2026/09/24 01:24:34 [error] 2111712#2111712: *30112376 access forbidden by rule, client: 35.189.34.2 ...
show more
2026/09/24 01:24:34 [error] 2111712#2111712: *30112376 access forbidden by rule, client: 35.189.34.26, server: behemoti.com, request: "GET /.codex/config.toml HTTP/2.0", host: "behemoti.com"
2026/09/24 01:24:34 [error] 2111716#2111716: *30112378 access forbidden by rule, client: 35.189.34.26, server: behemoti.com, request: "GET /old/.config/codex/auth.json HTTP/2.0", host: "behemoti.com"
2026/09/24 01:24:34 [error] 2111716#2111716: *30112377 access forbidden by rule, client: 35.189.34.26, server: behemoti.com, request: "GET /.claude/settings.local.json HTTP/2.0", host: "behemoti.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:19:59
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:19:52.895407 2026] [security2:error] [pid 1952:tid 1952] [client 35.189.34.26:39276] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.wvbigdaddy.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.wvbigdaddy.com"] [uri "/.codex/auth.json.bak"] [unique_id "arQmWCeFXOD0Ated2TOg6AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:27:52
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.34.26 (26.34.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:27:46.528669 2026] [security2:error] [pid 4726:tid 4726] [client 35.189.34.26:48476] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.jonnyonthespot.biz|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.jonnyonthespot.biz"] [uri "/.codex/auth.json.bak"] [unique_id "arQaIr1ih3znnW8G8mldlAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 14:24:25
(1 week ago)
[23/Sep/2026:17:24:24 +0300] -- 35.189.34.26 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /p ...
show more
[23/Sep/2026:17:24:24 +0300] -- 35.189.34.26 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /public/.claude/credentials.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-09-23 11:34:34
(1 week ago)
[Wed Sep 23 13:34:33.576888 2026] [security2:error] [pid 2795034:tid 2795039] [client 35.189.34.26:0 ...
show more
[Wed Sep 23 13:34:33.576888 2026] [security2:error] [pid 2795034:tid 2795039] [client 35.189.34.26:0] [client 35.189.34.26] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "api.sup.coop"] [uri "/api/.codex/auth.json"] [unique_id "arO5Sbre9BU1VC2ufdUS0QAAAAM"]
[Wed Sep 23 13:34:33.578080 2026] [security2:error] [pid 2795034:tid 2795044] [client 35.189.34.26:0] [client 35.189.34.26] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [ta
...
show less
Web App Attack
Bad Web Bot