Anonymous
2026-09-22 02:45:36
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-22 02:31:01
(1 day ago)
[ns1.moussaspartners.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/old/.codex/auth ...
show more
[ns1.moussaspartners.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/old/.codex/auth.json | /backup/.claude.json | /data/.claude.json
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:51:23
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 8.230.16.195 (195.16.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.230.16.195 (195.16.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:51:16.298089 2026] [security2:error] [pid 11808:tid 11808] [client 8.230.16.195:37784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||agenesis7.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "agenesis7.com"] [uri "/.codex/auth.json.old"] [unique_id "arHRBJEcw5w8nWxdoqq0LwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kkw
2026-09-21 20:17:32
(1 day ago)
[REDACTED] 8.230.16.195 - - [21/Sep/2026:22:17:31 +0200] "GET /backup/.claude/credentials.json HTTP/ ...
show more
[REDACTED] 8.230.16.195 - - [21/Sep/2026:22:17:31 +0200] "GET /backup/.claude/credentials.json HTTP/1.1" 404 4512 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:56:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 8.230.16.195 (195.16.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.230.16.195 (195.16.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:56:52.988244 2026] [security2:error] [pid 32052:tid 32052] [client 8.230.16.195:39604] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.taschstudios.com.saadeh.ws|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.taschstudios.com.saadeh.ws"] [uri "/.codex/auth.json.bak"] [unique_id "arGMBNBnS1PwlqMgo51GRQAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-21 16:02:32
(1 day ago)
Scan of vulnerable files
Web App Attack
๐ฏ๐ต
amyriad
2026-09-21 14:26:38
(2 days ago)
8.230.16.195 - - [21/Sep/2026:14:26:36 +0000] "GET /backup/.codex/auth.json HTTP/1.1" 404 437 "-" "c ...
show more
8.230.16.195 - - [21/Sep/2026:14:26:36 +0000] "GET /backup/.codex/auth.json HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
8.230.16.195 - - [21/Sep/2026:14:26:36 +0000] "GET /backup/.claude.json HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
8.230.16.195 - - [21/Sep/2026:14:26:37 +0000] "GET /backup/.claude/credentials.json HTTP/1.1" 404 437 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Hacking
Brute-Force
๐ณ๐ฑ
Savvii
2026-09-21 07:36:05
(2 days ago)
20 attempts against mh-misbehave-ban on comet
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 07:05:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack