🇺🇸
TPI-Abuse
2026-08-29 14:24:19
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.109.17.221 (221.17.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.17.221 (221.17.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 10:24:10.921346 2026] [security2:error] [pid 29646:tid 29646] [client 136.109.17.221:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.southernbroadcast.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apLripyf6dkOaZuqrjZT0wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-08-29 13:24:40
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-08-29 12:35:16
(5 hours ago)
80,443
Brute-Force
SSH
🇺🇸
azminawwar
2026-08-29 11:00:53
(7 hours ago)
[136.109.17.221] triggered by honeypot on port [80], Timestamp [2026-08-29T11:00:52Z]METHOD=GET PATH ...
show more
[136.109.17.221] triggered by honeypot on port [80], Timestamp [2026-08-29T11:00:52Z]METHOD=GET PATH=/ HTTP=HTTP/1.1 UA="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko
show less
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-08-29 10:30:30
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.109.17.221 (221.17.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.17.221 (221.17.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:30:24.716614 2026] [security2:error] [pid 28070:tid 28070] [client 136.109.17.221:2644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americaskitchencoachcom.indie100.com"] [uri "/@fs/app/.env"] [unique_id "apK0wIb0_e9_YVfX4yf9XgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 09:47:03
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.109.17.221 (221.17.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.17.221 (221.17.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:46:59.669664 2026] [security2:error] [pid 85660:tid 85767] [client 136.109.17.221:29064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.advantagepluscaregivers.richardleeweatherman.com"] [uri "/@fs/.env"] [unique_id "apKqky9rkZ20-YpRI9VHvAAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-29 09:43:26
(8 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/.env (+11 more) | 2026-08-29 09:43 UTC
show less
Hacking
Web App Attack
🇫🇷
mrcrassi
2026-08-29 09:25:37
(8 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /openai_key.json
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:150.10) Gecko/20100101 Firefox/150.10; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-08-29 09:22:30
(8 hours ago)
136.109.17.221 - - [29/Aug/2026:11:22:05 +0200] "GET HTTP/1.1" 403 1852 "-" "Mozilla/5.0 AppleWebKi ...
show more
136.109.17.221 - - [29/Aug/2026:11:22:05 +0200] "GET HTTP/1.1" 403 1852 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +https://openai.com/gptbot"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-08-29 09:00:01
(9 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
Anonymous
2026-08-29 08:49:44
(9 hours ago)
136.109.17.221 - - [29/Aug/2026:10:49:43 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.e ...
show more
136.109.17.221 - - [29/Aug/2026:10:49:43 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
136.109.17.221 - - [29/Aug/2026:10:49:43 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.2538.111 Mobile Safari/537.36; compatible; GPTBot/1.4; +https://openai.com/gptbot"
136.109.17.221 - - [29/Aug/2026:10:49:43 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot) Chrome/133.0.8143.242 Safari/537.36"
136.109.17.221 - - [29/Aug/2026:10:49:43 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; [email protected] )"
136.109.17.221 - - [29/Aug/2026:10:49:43 +0200] "
...
show less
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-08-29 08:32:37
(9 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 08:31:54
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.109.17.221 (221.17.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.17.221 (221.17.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:31:48.606421 2026] [security2:error] [pid 5027:tid 5027] [client 136.109.17.221:37312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.amychop.com"] [uri "/@fs/app/.env"] [unique_id "apKY9OX0NWzVLj3-Dj7CTwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-08-29 08:22:50
(9 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-08-29 08:22:27
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack