Anonymous
2026-09-08 03:49:11
(45 minutes ago)
Bot / seems abusive / Apache connections: 60
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:45:05
(49 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:44:57.614602 2026] [security2:error] [pid 26260:tid 26260] [client 136.108.80.178:48622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dictionaryoffish.com"] [uri "/@fs/app/.env"] [unique_id "ap-EuUw37kZ11r7SXuBGTgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:28:24
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:28:19.948482 2026] [security2:error] [pid 24587:tid 24587] [client 136.108.80.178:59738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.faithlines.com"] [uri "/@fs/.env"] [unique_id "ap-A03uzTTEbDxptQBoObQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:54:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:54:35.954666 2026] [security2:error] [pid 2796508:tid 2796508] [client 136.108.80.178:54704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.fixitz.net"] [uri "/@fs/src/.env"] [unique_id "ap94656rDVdOci7urfJL8AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 02:43:30
(1 hour ago)
136.108.80.178 - - [08/Sep/2026:04:43:05 +0200] "GET HTTP/1.1" 403 1856 "-" "Mozilla/5.0 AppleWebKi ...
show more
136.108.80.178 - - [08/Sep/2026:04:43:05 +0200] "GET HTTP/1.1" 403 1856 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:00:15
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:00:08.721997 2026] [security2:error] [pid 21342:tid 21342] [client 136.108.80.178:63664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wadenelson.com"] [uri "/@fs/app/.env"] [unique_id "ap9sKK39wP5IFB-OAG-YJgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
middelkoopcc
2026-09-08 01:37:00
(2 hours ago)
2026-09-08 03:35:20 GET /@fs/root/.env?raw?? [301] && 2026-09-08 03:35:20 GET /@fs/..%252f..%252f..% ...
show more
2026-09-08 03:35:20 GET /@fs/root/.env?raw?? [301] && 2026-09-08 03:35:20 GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? [301] && 2026-09-08 03:35:20 GET /@fs/.env.production?raw?? [301] && 132 more within 20 minutes
show less
Web App Attack
🇬🇧
consul.to
2026-09-08 00:43:50
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 00:40:40
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:40:33.391625 2026] [security2:error] [pid 26875:tid 26875] [client 136.108.80.178:65394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.concentricsteel.com"] [uri "/@fs/.env"] [unique_id "ap9ZgS_V7ns9MAz6haxFhAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-08 00:37:58
(3 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.save
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) Chrome/118.0.3590.60 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-08 00:19:22
(4 hours ago)
Aggressive web scan
Web App Attack
🇧🇪
cmbplf
2026-09-08 00:13:27
(4 hours ago)
9.207 4xx requests in 1 hour (3d16h7m)
Brute-Force
Bad Web Bot
🇺🇸
mnsf
2026-09-08 00:05:24
(4 hours ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 23:57:23
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.80.178 (178.80.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:57:15.826748 2026] [security2:error] [pid 30914:tid 30914] [client 136.108.80.178:53446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.buckinghambar.com"] [uri "/@fs/src/.env"] [unique_id "ap9PWzkpXCvpKLITQjgi1AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 23:56:12
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking