๐ซ๐ท
masterguru
2026-09-22 06:01:33
(1 day ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-195)
Hacking
๐บ๐ธ
Mundo Bueno
2026-09-22 05:09:01
(1 day ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /old/.config/codex/auth.json [RATE LIMITED - 1800s quara ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /old/.config/codex/auth.json [RATE LIMITED - 1800s quarantine] | Pays: FI | UA: crusader-worker/1.0
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:48:00
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.228.188.237 (237.188.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.228.188.237 (237.188.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:47:54.854953 2026] [security2:error] [pid 3059:tid 3059] [client 35.228.188.237:43076] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stable-vitals.com.untraceable.org|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stable-vitals.com.untraceable.org"] [uri "/.codex/auth.json.bak"] [unique_id "arHeShkOTs8fwovb99zB5QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 01:28:47
(1 day ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 23:54:49
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 22:53:48
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.228.188.237 (237.188.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.228.188.237 (237.188.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:53:42.477234 2026] [security2:error] [pid 8517:tid 8527] [client 35.228.188.237:59216] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||trust-more.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "trust-more.com"] [uri "/.codex/auth.json.bak"] [unique_id "arG1dme8CTWTIbhP1u4fRwAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 18:15:22
(1 day ago)
20 attempts against mh-misbehave-ban on apt
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-21 17:20:03
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-21 16:53:03
(1 day ago)
35.228.188.237 - - [21/Sep/2026:18:53:00 +0200] "GET /public/.codex/auth.json HTTP/1.1" 404 4433 "-" ...
show more
35.228.188.237 - - [21/Sep/2026:18:53:00 +0200] "GET /public/.codex/auth.json HTTP/1.1" 404 4433 "-" "crusader-worker/1.0"
35.228.188.237 - - [21/Sep/2026:18:53:00 +0200] "GET /app/.claude/credentials.json HTTP/1.1" 404 4433 "-" "crusader-worker/1.0"
35.228.188.237 - - [21/Sep/2026:18:53:00 +0200] "GET /old/.codex/auth.json HTTP/1.1" 404 4431 "-" "crusader-worker/1.0"
35.228.188.237 - - [21/Sep/2026:18:53:00 +0200] "GET /wwwroot/.codex/auth.json HTTP/1.1" 404 4431 "-" "crusader-worker/1.0"
35.228.188.237 - - [21/Sep/2026:18:53:00 +0200] "GET /html/.codex/auth.json HTTP/1.1" 404 4432 "-" "crusader-worker/1.0"
35.228.188.237 - - [21/Sep/2026:18:53:00 +0200] "GET /old/.claude/credentials.json HTTP/1.1" 404 4431 "-" "crusader-worker/1.0"
35.228.188.237 - - [21/Sep/2026:18:53:00 +0200] "GET /html/.claude.json HTTP/1.1" 404 4431 "-" "crusader-worker/1.0"
35.228.188.237 - - [21/Sep/2026:18:53:00 +0200] "GET /home/.codex/auth.json HTTP/1.1" 404 4431 "-" "crusader-worker/1.0"
35.228.188.237 - -
show less
Bad Web Bot
๐ซ๐ท
pm33
2026-09-21 15:33:11
(1 day ago)
Unauthorized connections HTTP 403
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-21 11:32:38
(1 day ago)
Malicious activity from IP detected: crowdsecurity/http-probing.
Web App Attack
Hacking
๐ฉ๐ช
LRob
2026-09-21 09:22:29
(1 day ago)
Connection flood: far more simultaneous connections than any client needs, dropped by the server | 2 ...
show more
Connection flood: far more simultaneous connections than any client needs, dropped by the server | 2026-09-21 09:22 UTC
show less
DDoS Attack
๐ฎ๐น
VHosting
2026-09-21 03:05:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack