๐ช๐ธ
pipeline.es
2026-09-24 08:59:27
(16 hours ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:53:22
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.228.184.246 (246.184.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.228.184.246 (246.184.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:53:17.722329 2026] [security2:error] [pid 31934:tid 31934] [client 35.228.184.246:32890] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||box903.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "box903.com"] [uri "/.codex/auth.json.old"] [unique_id "arS6zaX5nIR143dzQ_6gRgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-24 03:17:37
(22 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-09-24 02:00:05
(23 hours ago)
categories: DDoS Attack
DDoS Attack
๐ช๐ธ
pipeline.es
2026-09-24 01:59:17
(23 hours ago)
Web scanning / probing for vulnerable paths | URL: /config/.codex/auth.json | Evidence: bestravel.on ...
show more
Web scanning / probing for vulnerable paths | URL: /config/.codex/auth.json | Evidence: bestravel.online 35.228.184.246 - - [24/Sep/2026:03:58:42 +0200] \"GET /config/.codex/auth.json HTTP/1.1\" 404 4658 \"-\" \"crusader-worker/1.0\" GEOIP_COUNTRY_CODE=FI | ASN: GOOGLE-CLOUD-PLATFORM | Country: FI
show less
Port Scan
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-24 01:50:01
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:08:13
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.228.184.246 (246.184.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.228.184.246 (246.184.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:08:07.749658 2026] [security2:error] [pid 12008:tid 12008] [client 35.228.184.246:56856] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barabesi.net|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barabesi.net"] [uri "/.codex/auth.json.bak"] [unique_id "arRp58VIy9pJzK3Xrnjo2AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
borbolla
2026-09-23 19:28:37
(1 day ago)
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.claude.json HTTP/1.1" "G ...
show more
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.claude.json HTTP/1.1" "GET /.claude/.credentials.json HTTP/1.1" "GET /.claude/credentials.json HTTP/1.1"
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-09-23 18:14:43
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 15:17:29
(1 day ago)
[23/Sep/2026:18:17:29 +0300] -- 35.228.184.246 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[23/Sep/2026:18:17:29 +0300] -- 35.228.184.246 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.codex/auth.json.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:25:18
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.228.184.246 (246.184.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.228.184.246 (246.184.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:25:15.193842 2026] [security2:error] [pid 9434:tid 9434] [client 35.228.184.246:40726] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aquascapes.net|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aquascapes.net"] [uri "/.codex/auth.json.bak"] [unique_id "arPhS348lSmyTogH49YzjAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 10:39:37
(1 day ago)
[livebd] Excessive 404 errors (web scanning): 31 suspicious requests detected by fail2ban jail apach ...
show more
[livebd] Excessive 404 errors (web scanning): 31 suspicious requests detected by fail2ban jail apache-404. Example: 35.228.184.246 - - [23/Sep/2026:12:39:17 +0200] "GET /.codex/auth.json.bak HTTP/1.1" 404 7867 "-" "crusader-worker/1.0"
35.228.184.246 - - [23/Sep/2026:12:39:17 +0200] "GET /.codex/auth.json.old HTTP/1.1" 404 7867 "-" "crusader-worker/1.0"
35.228.184.246 - - [23/Sep/2026:12:39:17 +0200] "GET /.codex/auth.json HTTP/1.1" 404 7867 "-" "crusader-worker/1.0"
35.228.184.246 - - [23/Sep/2026:12:39:17 +0200] "GET /.codex/config.toml HTTP/1.1" 404 7867 "-" "crusader-worker/1.0"
35.228.184.246 - - [23/Sep/2026:12:39:17 +0200] "GET /.config/codex/auth.json HTTP/1.1" 404 7867 "-" "crusader-worker/1.0"
35.228.184.246 - - [23/Sep/2026:12:
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-23 08:00:50
(1 day ago)
807 requests with url.path */auth.json
Brute-Force
Bad Web Bot
๐ฌ๐ง
abivia
2026-09-23 07:42:48
(1 day ago)
Abivia WAF trigger: Rule scriptKiddies: Credential probing uri: /.claude/settings.json
Hacking
๐ฆ๐บ
artful
2026-09-23 03:47:00
(1 day ago)
Excessive errors, high load and multiple hits per second
Web App Attack