๐ฌ๐ง
thetomtaylor.co.uk
2026-09-24 13:08:00
(8 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02]
Hacking
SQL Injection
Web App Attack
๐ซ๐ท
IRISIO
2026-09-24 06:32:46
(14 hours ago)
scans/SQL injection/spam posts : 100 queries
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-24 06:17:51
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.221.213.13 (13.213.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.213.13 (13.213.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:17:46.722949 2026] [security2:error] [pid 13091:tid 13091] [client 35.221.213.13:36030] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brazilianbikinis.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brazilianbikinis.com"] [uri "/.codex/auth.json.bak"] [unique_id "arTAimICVSESZ2BJUFW4pwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-09-24 05:28:48
(15 hours ago)
HTTP vulnerability scanning
Web App Attack
๐ฆ๐บ
neilwal
2026-09-24 02:28:00
(18 hours ago)
Web Probe (443): beyondzugzwang.myvnc.com:443 35.221.213.13 - - [24/Sep/2026:12:27:59 +1000] "GET /. ...
show more
Web Probe (443): beyondzugzwang.myvnc.com:443 35.221.213.13 - - [24/Sep/2026:12:27:59 +1000] "GET /.config/claude/credentials.json HTTP/1.1" 401 4755 "-" "crusader-worker/1.0"
beyondzugzwang.myvnc.com:443 35.221.213.13 - - [24/Sep/2026:12:27:59 +1000] "GET /.config/codex/auth.json HTTP/1.1" 401 4755 "-" "crusader-worker/1.0"
beyondzugzwang.myvnc.com:443 35.221.213.13 - - [24/Sep/2026:12:27:59 +1000] "GET /old/.config/codex/auth.json HTTP/1.1" 401 4755 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-24 02:05:04
(19 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [wa01]
Hacking
SQL Injection
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 01:32:44
(19 hours ago)
473 requests with url.path */auth.json
200 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 01:09:11
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.221.213.13 (13.213.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.213.13 (13.213.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:09:06.115752 2026] [security2:error] [pid 7813:tid 7813] [client 35.221.213.13:54618] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||beach98.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "beach98.com"] [uri "/.codex/auth.json.bak"] [unique_id "arR4Mp-WVw_WrW13zn82RgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-24 01:07:01
(20 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [wa02]
Hacking
SQL Injection
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-24 00:19:30
(21 hours ago)
20 attempts against mh-misbehave-ban on pf221113
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 15:09:25
(1 day ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.art25.gr; logs=/var/log/httpd/domains/art25.gr.log; samp ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.art25.gr; logs=/var/log/httpd/domains/art25.gr.log; samples=/.codex/auth.json | /.codex/auth.json.save | /.claude/.credentials.json
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:55:18
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.221.213.13 (13.213.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.213.13 (13.213.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:55:11.711652 2026] [security2:error] [pid 4221:tid 4269] [client 35.221.213.13:47426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arizonasolutionsgroup.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arizonasolutionsgroup.com"] [uri "/.codex/auth.json.old"] [unique_id "arPoT9vml7RpJh3mN4mowQAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-09-23 14:51:01
(1 day ago)
categories: DDoS Attack
DDoS Attack
๐ฎ๐น
VHosting
2026-09-23 05:25:06
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 05:01:31
(1 day ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack