๐บ๐ธ
mnsf
2026-09-24 06:05:18
(2 seconds ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-24 05:20:20
(45 minutes ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /backup/.claude/credentials.json (+14 more) | 2026-09-24 05:20 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:02:54
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.88.140 (140.88.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.88.140 (140.88.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:02:46.859655 2026] [security2:error] [pid 3048:tid 3048] [client 35.199.88.140:45428] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blfmarine.com.lakesidedetectiveagency.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blfmarine.com.lakesidedetectiveagency.com"] [uri "/.codex/auth.json.bak"] [unique_id "arSg5qC5xBNkBTsRKpwaDwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:05:13
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.88.140 (140.88.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.88.140 (140.88.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:05:10.136769 2026] [security2:error] [pid 12455:tid 12455] [client 35.199.88.140:56722] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bikiniadvice.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bikiniadvice.com"] [uri "/.codex/auth.json.old"] [unique_id "arSTZl_T9FDGupDKoNm0EQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-24 01:50:03
(4 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:40:06
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.88.140 (140.88.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.88.140 (140.88.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:39:58.546997 2026] [security2:error] [pid 7288:tid 7288] [client 35.199.88.140:39022] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bennefeld.k0cgy.net|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bennefeld.k0cgy.net"] [uri "/.codex/auth.json.bak"] [unique_id "arR_bg1_dUUa5uWPSZIO0wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-24 00:14:04
(5 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-201)
show less
Hacking
๐ฉ๐ช
Marco711
2026-09-23 17:35:59
(12 hours ago)
port/URL scanning
Port Scan
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 11:41:24
(18 hours ago)
[livebd] Excessive 404 errors (web scanning): 31 suspicious requests detected by fail2ban jail apach ...
show more
[livebd] Excessive 404 errors (web scanning): 31 suspicious requests detected by fail2ban jail apache-404. Example: 35.199.88.140 - - [23/Sep/2026:13:41:16 +0200] "GET /.codex/auth.json.old HTTP/1.1" 404 7789 "-" "crusader-worker/1.0"
35.199.88.140 - - [23/Sep/2026:13:41:16 +0200] "GET /.config/codex/auth.json HTTP/1.1" 404 7789 "-" "crusader-worker/1.0"
35.199.88.140 - - [23/Sep/2026:13:41:16 +0200] "GET /.codex/auth.json~ HTTP/1.1" 404 7789 "-" "crusader-worker/1.0"
35.199.88.140 - - [23/Sep/2026:13:41:16 +0200] "GET /.codex/auth.json HTTP/1.1" 404 7789 "-" "crusader-worker/1.0"
35.199.88.140 - - [23/Sep/2026:13:41:16 +0200] "GET /.codex/config.toml HTTP/1.1" 404 7789 "-" "crusader-worker/1.0"
35.199.88.140 - - [23/Sep/2026:13:41:16 +0200] "GET /.codex/auth.js
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
antivoid.xyz
2026-09-23 09:02:06
(21 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 08:45:55
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.88.140 (140.88.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.88.140 (140.88.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 04:45:51.820728 2026] [security2:error] [pid 6819:tid 6819] [client 35.199.88.140:47250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||annakahle.click|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "annakahle.click"] [uri "/.codex/auth.json.old"] [unique_id "arORv-S7Jcsyk2LPxHcZSgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 07:45:58
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.88.140 (140.88.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.88.140 (140.88.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 03:45:54.532484 2026] [security2:error] [pid 20634:tid 20771] [client 35.199.88.140:57744] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanacademyofprojectmanagement.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanacademyofprojectmanagement.com"] [uri "/.codex/auth.json.old"] [unique_id "arODshlN6hQqjqGjvnajaAAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 07:18:32
(22 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐บ๐ธ
wordpresshosting.solutions
2026-09-23 02:39:50
(1 day ago)
Web brute-force / failed auth detected. Evidence: [Wed Sep 23 02:39:49.901785 2026] [authz_core:erro ...
show more
Web brute-force / failed auth detected. Evidence: [Wed Sep 23 02:39:49.901785 2026] [authz_core:error] [pid 3459917] [client [IP]:0] AH01630: client [IP]nied by server configuration: proxy:http://[IP]:18081/.codex/auth.json~
[Wed Sep 23 02:39:49.909961 2026] [authz_core:error] [pid 3459899] [client [IP]:0] AH01630: client [IP]nied by server configuration: proxy:http://[IP]:18081/.codex/auth.json.save
show less
Brute-Force
Web App Attack
Anonymous
2026-09-23 02:35:07
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking