๐ซ๐ฎ
paissangroup
2026-09-24 09:08:52
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 09:04:30
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.240.245.244 (244.245.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.245.244 (244.245.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:04:26.388566 2026] [security2:error] [pid 2240:tid 2240] [client 35.240.245.244:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||camerabshk.365soft.top|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "camerabshk.365soft.top"] [uri "/.codex/auth.json.old"] [unique_id "arTnmozRz7OwjU_e5R8AIQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-24 06:50:04
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-24 06:22:12
(1 week ago)
35.240.245.244 - - [24/Sep/2026:08:22:08 +0200] "GET /html/.claude.json HTTP/1.1" 404 4471 "-" "crus ...
show more
35.240.245.244 - - [24/Sep/2026:08:22:08 +0200] "GET /html/.claude.json HTTP/1.1" 404 4471 "-" "crusader-worker/1.0"
35.240.245.244 - - [24/Sep/2026:08:22:08 +0200] "GET /web/.codex/auth.json HTTP/1.1" 404 4471 "-" "crusader-worker/1.0"
35.240.245.244 - - [24/Sep/2026:08:22:08 +0200] "GET /root/.codex/auth.json HTTP/1.1" 404 4470 "-" "crusader-worker/1.0"
35.240.245.244 - - [24/Sep/2026:08:22:08 +0200] "GET /wwwroot/.codex/auth.json HTTP/1.1" 404 4472 "-" "crusader-worker/1.0"
35.240.245.244 - - [24/Sep/2026:08:22:08 +0200] "GET /home/.codex/auth.json HTTP/1.1" 404 4471 "-" "crusader-worker/1.0"
35.240.245.244 - - [24/Sep/2026:08:22:08 +0200] "GET /uploads/.codex/auth.json HTTP/1.1" 404 4470 "-" "crusader-worker/1.0"
35.240.245.244 - - [24/Sep/2026:08:22:08 +0200] "GET /files/.codex/auth.json HTTP/1.1" 404 4472 "-" "crusader-worker/1.0"
35.240.245.244 - - [24/Sep/2026:08:22:08 +0200] "GET /opt/.codex/auth.json HTTP/1.1" 404 4471 "-" "crusader-worker/1.0"
35.240.245.244 - - [24/Sep/2026
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 06:04:09
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.240.245.244 (244.245.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.245.244 (244.245.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:04:04.094341 2026] [security2:error] [pid 25720:tid 25720] [client 35.240.245.244:57618] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bradsalerno.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bradsalerno.com"] [uri "/.codex/auth.json.bak"] [unique_id "arS9VN-QhSE-opqFcbQC7gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-24 05:14:43
(1 week ago)
8 attacks on password/key grabbing URLs:
GET /public/.claude/credentials.json HTTP/1.1
Hacking
๐ณ๐ฑ
Savvii
2026-09-24 01:53:12
(1 week ago)
20 attempts against mh_ha-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 01:27:58
(1 week ago)
958 requests with url.path */auth.json
249 requests with url.path *credentials.json
158 requests ...
show more
958 requests with url.path */auth.json
249 requests with url.path *credentials.json
158 requests with url.path *.config/*
show less
Brute-Force
Bad Web Bot
Anonymous
2026-09-24 00:10:21
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 21:55:16
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.240.245.244 (244.245.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.245.244 (244.245.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:55:11.588690 2026] [security2:error] [pid 21774:tid 21774] [client 35.240.245.244:42634] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aylinvictoria.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aylinvictoria.com"] [uri "/.codex/auth.json.bak"] [unique_id "arRKvw7t2RaIpDII9_G3zAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
seal
2026-09-23 17:41:34
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
SSH
Brute-Force
Anonymous
2026-09-23 14:24:00
(1 week ago)
35.240.245.244 - - [23/Sep/2026:22:23:59 +0800] "GET /.config/codex/auth.json HTTP/1.1" 404 196 "-" ...
show more
35.240.245.244 - - [23/Sep/2026:22:23:59 +0800] "GET /.config/codex/auth.json HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 08:39:18
(1 week ago)
Restricted File Access Attempt. Matched phrase "credentials.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 07:09:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.240.245.244 (244.245.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.245.244 (244.245.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 03:09:05.726020 2026] [security2:error] [pid 28482:tid 28482] [client 35.240.245.244:39210] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alltecmachine.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alltecmachine.com"] [uri "/.codex/auth.json.bak"] [unique_id "arN7EXrF-nzWap5Vlpnn5wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-23 06:19:03
(1 week ago)
[WedSep2308:18:57.6126712026][security2:error][pid1805107:tid1805217][client35.240.245.244:0]ModSecu ...
show more
[WedSep2308:18:57.6126712026][security2:error][pid1805107:tid1805217][client35.240.245.244:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"akastudio.ch\"][uri\"/.codex/auth.json.bak\"][unique_id\"arNvUYiJSq7IC8p7kQqqnwAAAMA\"]
show less
Port Scan
Brute-Force
Web App Attack