๐บ๐ธ
TPI-Abuse
2026-09-24 07:29:32
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.20.29 (29.20.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.20.29 (29.20.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:29:27.694880 2026] [security2:error] [pid 17480:tid 17503] [client 35.237.20.29:54220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||busybeerestaurant.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "busybeerestaurant.com"] [uri "/.codex/auth.json.bak"] [unique_id "arTRVwPtErTfiJ0gzQ21CAAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:23:29
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.20.29 (29.20.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.20.29 (29.20.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:23:24.501970 2026] [security2:error] [pid 4531:tid 4531] [client 35.237.20.29:40756] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brickyardinn.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brickyardinn.com"] [uri "/.codex/auth.json.bak"] [unique_id "arTB3DbNNn9nrvXKQ14ngQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-24 01:35:33
(13 hours ago)
Restricted File Access Attempt: AI Coding Assistant Artifact. Matched phrase ".claude/" at REQUEST_F ...
show more
Restricted File Access Attempt: AI Coding Assistant Artifact. Matched phrase ".claude/" at REQUEST_FILENAME. (930140-201)
show less
Hacking
๐ง๐ช
cmbplf
2026-09-24 01:28:18
(13 hours ago)
703 requests with url.path */auth.json
307 requests with url.path *credentials.json
148 requests ...
show more
703 requests with url.path */auth.json
307 requests with url.path *credentials.json
148 requests with url.path *.config/*
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 00:29:26
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.20.29 (29.20.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.20.29 (29.20.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:29:23.024600 2026] [security2:error] [pid 29006:tid 29024] [client 35.237.20.29:34124] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bayareajazzandbluesicians.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bayareajazzandbluesicians.com"] [uri "/.codex/auth.json.old"] [unique_id "arRu4_ZhgLilEbA1WTW7wwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 21:32:17
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-09-23 17:05:41
(22 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
Anonymous
2026-09-23 12:37:57
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-09-23 08:08:00
(1 day ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 05:47:55
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.20.29 (29.20.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.20.29 (29.20.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 01:47:49.701359 2026] [security2:error] [pid 14594:tid 14594] [client 35.237.20.29:36690] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||aifactoid.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aifactoid.com"] [uri "/.codex/auth.json.old"] [unique_id "arNoBXj-lwYoyveSKdU0IQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 08:45:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack