๐ง๐ช
Ivo Vynckier
2026-09-24 13:02:00
(1 week ago)
35.228.107.8 - - [24/Sep/2026:04:28:48 +0200] "GET /opt/.codex/auth.json HTTP/1.1" 404 5550 "-" "cru ...
show more
35.228.107.8 - - [24/Sep/2026:04:28:48 +0200] "GET /opt/.codex/auth.json HTTP/1.1" 404 5550 "-" "crusader-worker/1.0"
35.228.107.8 - - [24/Sep/2026:04:28:48 +0200] "GET /.codex/auth.json.save HTTP/1.1" 404 5550 "-" "crusader-worker/1.0"
35.228.107.8 - - [24/Sep/2026:04:28:48 +0200] "GET /app/.claude/credentials.json HTTP/1.1" 404 5550 "-" "crusader-worker/1.0"
35.228.107.8 - - [24/Sep/2026:04:28:48 +0200] "GET /files/.codex/auth.json HTTP/1.1" 404 5550 "-" "crusader-worker/1.0"
35.228.107.8 - - [24/Sep/2026:04:28:48 +0200] "GET /.codex/auth.json.bak HTTP/1.1" 404 5550 "-" "crusader-worker/1.0"
35.228.107.8 - - [24/Sep/2026:04:28:48 +0200] "GET /.claude/settings.local.json HTTP/1.1" 404 5550 "-" "crusader-worker/1.0"
35.228.107.8 - - [24/Sep/2026:04:28:48 +0200] "GET /.codex/auth.json.old HTTP/1.1" 404 5550 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ฌ๐ง
rakkor
2026-09-24 09:23:13
(1 week ago)
2026/09/24 10:23:11 [error] 20669#20669: *7816186 open() "/usr/syno/synoman/codex/auth.json" failed ...
show more
2026/09/24 10:23:11 [error] 20669#20669: *7816186 open() "/usr/syno/synoman/codex/auth.json" failed (2: No such file or directory), client: 35.228.107.8, server: cam.rakkor.uk, request: "GET /codex/auth.json HTTP/1.1", host: "cam.rakkor.uk"
2026/09/24 10:23:11 [error] 20667#20667: *7816185 open() "/usr/syno/synoman/old/.claude/credentials.json" failed (2: No such file or directory), client: 35.228.107.8, server: cam.rakkor.uk, request: "GET /old/.claude/credentials.json HTTP/1.1", host: "cam.rakkor.uk"
...
show less
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:10:54
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.228.107.8 (8.107.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.228.107.8 (8.107.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:10:47.465237 2026] [security2:error] [pid 13987:tid 13987] [client 35.228.107.8:38704] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||buggyshop.org|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "buggyshop.org"] [uri "/.codex/auth.json.bak"] [unique_id "arTM9wk8y8H5_0vO_O8fngAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-24 02:27:06
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:32:49
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.228.107.8 (8.107.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.228.107.8 (8.107.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:32:41.745753 2026] [security2:error] [pid 16353:tid 16353] [client 35.228.107.8:46674] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bazzoli.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bazzoli.com"] [uri "/.codex/auth.json.bak"] [unique_id "arRvqVNLdgthEs99i18LowAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-24 00:14:26
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:16:24
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.228.107.8 (8.107.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.228.107.8 (8.107.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:16:16.271454 2026] [security2:error] [pid 15610:tid 15610] [client 35.228.107.8:48600] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.westernmassaa.net|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.westernmassaa.net"] [uri "/.codex/auth.json.old"] [unique_id "arQlgHGRsV71wELsLKNL_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-09-23 08:33:02
(1 week ago)
categories: DDoS Attack
DDoS Attack
Anonymous
2026-09-23 07:04:49
(1 week ago)
Web application attack detected.
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 06:37:08
(1 week ago)
Restricted File Access Attempt. Matched phrase "credentials.json" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-23 06:25:03
(1 week ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 05:30:55
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.228.107.8 (8.107.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.228.107.8 (8.107.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 01:30:48.222830 2026] [security2:error] [pid 13712:tid 13712] [client 35.228.107.8:40562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||agrizel.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "agrizel.com"] [uri "/.codex/auth.json.bak"] [unique_id "arNkCIvIrBEKJRXSYXV3gQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-23 01:17:55
(1 week ago)
20 attempts against mh_ha-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-22 14:01:14
(1 week ago)
20 attempts against mh-misbehave-ban on orcus
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:07:30
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.228.107.8 (8.107.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.228.107.8 (8.107.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:07:22.832828 2026] [security2:error] [pid 29151:tid 29151] [client 35.228.107.8:55542] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||1st-advantage-arkansas-real-estate-school.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "1st-advantage-arkansas-real-estate-school.com"] [uri "/.codex/auth.json.bak"] [unique_id "arJvejOZLFRgYCM9j4IIwwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack