๐บ๐ธ
raymarron.com
2026-09-22 13:53:38
(1 week ago)
50x probes for various vulnerabilities.
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 06:05:27
(1 week ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 03:46:42
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 8.234.175.84 (84.175.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.175.84 (84.175.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 23:46:36.364539 2026] [security2:error] [pid 16421:tid 16421] [client 8.234.175.84:49926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jeremy-olson.com|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jeremy-olson.com"] [uri "/.codex/auth.json.old"] [unique_id "arH6HFIHRgkw96xHylCGoQAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-22 01:45:43
(1 week ago)
(modsecurity) srv103 ModSecurity 8.234.175.84 (US/United States/84.175.234.8.bc.googleusercontent.co ...
show more
(modsecurity) srv103 ModSecurity 8.234.175.84 (US/United States/84.175.234.8.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:34:22
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 8.234.175.84 (84.175.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.175.84 (84.175.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:34:18.654506 2026] [security2:error] [pid 20931:tid 20931] [client 8.234.175.84:46668] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.en.coveyhillenterprises.com|F|2"] [data ".json.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.en.coveyhillenterprises.com"] [uri "/.codex/auth.json.bak"] [unique_id "arHbGlBUizhcB2JkaetQBwAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:08:01
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 8.234.175.84 (84.175.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.234.175.84 (84.175.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:07:37.915326 2026] [security2:error] [pid 25433:tid 25433] [client 8.234.175.84:46048] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bot.rustyog.net|F|2"] [data ".json.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bot.rustyog.net"] [uri "/.codex/auth.json.old"] [unique_id "arHGyUszh8K4rxitV29HYwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 22:24:35
(1 week ago)
[livebd] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apach ...
show more
[livebd] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 8.234.175.84 - - [22/Sep/2026:00:24:34 +0200] "GET /.codex/auth.json HTTP/1.1" 404 16957 "-" "crusader-worker/1.0"
8.234.175.84 - - [22/Sep/2026:00:24:34 +0200] "GET /.codex/config.toml HTTP/1.1" 404 16957 "-" "crusader-worker/1.0"
8.234.175.84 - - [22/Sep/2026:00:24:34 +0200] "GET /.codex/auth.json.bak HTTP/1.1" 404 16957 "-" "crusader-worker/1.0"
8.234.175.84 - - [22/Sep/2026:00:24:34 +0200] "GET /.codex/config.json HTTP/1.1" 404 16957 "-" "crusader-worker/1.0"
8.234.175.84 - - [22/Sep/2026:00:24:34 +0200] "GET /.codex/auth.json.old HTTP/1.1" 404 16957 "-" "crusader-worker/1.0"
apiwerkbon-belderi
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-21 20:45:18
(1 week ago)
(modsecurity) srv104 ModSecurity 8.234.175.84 (US/United States/84.175.234.8.bc.googleusercontent.co ...
show more
(modsecurity) srv104 ModSecurity 8.234.175.84 (US/United States/84.175.234.8.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-09-21 20:13:34
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-21 18:48:30
(1 week ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 15:30:44
(1 week ago)
[da.kdns.gr] httpd-config-scan: sites=www.webfly.gr; logs=/var/log/httpd/domains/webfly.gr.log; samp ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.webfly.gr; logs=/var/log/httpd/domains/webfly.gr.log; samples=/.config/claude/credentials.json | /.codex/auth.json | /.claude/credentials.json
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 09:33:37
(1 week ago)
Restricted File Access Attempt. Matched phrase "/auth.json" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 07:57:01
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.234.175.84 (US/United States/84.175 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.234.175.84 (US/United States/84.175.234.8.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-09-21 05:14:18
(1 week ago)
8 attacks on password/key grabbing URLs:
GET /www/.claude/credentials.json HTTP/1.1
Hacking
๐ฎ๐น
VHosting
2026-09-21 04:15:08
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack