Anonymous
2026-09-30 13:45:14
(3 hours ago)
Observed scanned 103 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.env, /.env.local, /.env.old, / ...
show more
Observed scanned 103 known-sensitive endpoint(s), e.g.: /, /%2eenv, /.env, /.env.local, /.env.old, /.env.prod
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 04:30:02
(12 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:29:55
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.66.252.88 (88.252.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.252.88 (88.252.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:29:51.712989 2026] [security2:error] [pid 7966:tid 7966] [client 136.66.252.88:53784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pixelspective.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pixelspective.com"] [uri "/z9x8c7v6b5-debug-trigger-pixelspective.com"] [unique_id "aryQP-euB0d7mUS5pwyO2gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 03:56:41
(13 hours ago)
136.66.252.88 - - [30/Sep/2026:03:55:56 +0000] "GET /@fs/../.env?raw?? HTTP/2.0" 403 49583 "-" "Mozi ...
show more
136.66.252.88 - - [30/Sep/2026:03:55:56 +0000] "GET /@fs/../.env?raw?? HTTP/2.0" 403 49583 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "-"
136.66.252.88 - - [30/Sep/2026:03:55:56 +0000] "GET /@fs/src/.env?raw?? HTTP/2.0" 403 49523 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "-"
136.66.252.88 - - [30/Sep/2026:03:55:57 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0" 403 49585 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "-"
136.66.252.88 - - [30/Sep/2026:03:55:57 +0000] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 403 49592 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-"
136.66.252.88 - - [30/Sep/2026:03:55:57 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/2.0" 403 49590 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-"
...
show less
Web App Attack
๐จ๐ฑ
Fernando Soto
2026-09-30 03:05:27
(14 hours ago)
WAF propio vps1 (CL): realtime_sensx102 score 20 en 1h. sondeo rutas sensibles.
Web App Attack
๐ซ๐ฎ
etasoft
2026-09-30 02:27:32
(14 hours ago)
Auto-blocked by WP Security AI: Rate limit: 4 violaciones
Bad Web Bot
๐จ๐ฆ
Mediashaker
2026-09-30 01:21:09
(16 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.66.252.88 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.66.252.88 (US/United States/88.252.66.136.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 00:39:51
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.66.252.88 (88.252.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.252.88 (88.252.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:39:47.415885 2026] [security2:error] [pid 28923:tid 28923] [client 136.66.252.88:42788] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||spacebooger.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "spacebooger.com"] [uri "/z9x8c7v6b5-debug-trigger-spacebooger.com"] [unique_id "arxaU4L7TnfnzUthNun7PAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-09-29 23:55:32
(17 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
Anonymous
2026-09-29 23:30:06
(17 hours ago)
CrowdSec decision: LePresidente/http-generic-401-bf (origin: crowdsec)
Port Scan
๐ง๐ช
cmbplf
2026-09-29 23:22:44
(18 hours ago)
3.388 requests from abuseipdb.com blacklisted IP (3mos6d55m)
Brute-Force
Bad Web Bot
Anonymous
2026-09-29 23:09:11
(18 hours ago)
Bot / seems abusive / Apache connections: 31
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-29 22:40:18
(18 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-29 22:32:04
(18 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php
UA: Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ท
radardatelecom
2026-09-29 22:26:02
(18 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack