๐ณ๐ฑ
homeshowdomain.nl
2026-10-01 21:59:09
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-30.
show less
Web App Attack
SSH
Hacking
๐ง๐ท
radardatelecom
2026-09-30 22:26:04
(1 day ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-30 21:59:44
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-30
Web App Attack
SSH
Hacking
Anonymous
2026-09-30 05:06:45
(1 day ago)
136.69.156.39 - - [30/Sep/2026:00:06:44 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "DuckAssi ...
show more
136.69.156.39 - - [30/Sep/2026:00:06:44 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" 136.69.156.39
136.69.156.39 - - [30/Sep/2026:00:06:44 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" 136.69.156.39
136.69.156.39 - - [30/Sep/2026:00:06:44 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 136.69.156.39
136.69.156.39 - - [30/Sep/2026:00:06:44 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" 136.69.156.39
136.69.156.39 - - [30/Sep/2026:00:06:44 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 136.69.156.39
136.69.156.39 - - [3
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-30 05:05:26
(1 day ago)
Abuse Detected (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-30 04:49:02
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 02:58:18
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.69.156.39 (39.156.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.156.39 (39.156.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:58:12.419978 2026] [security2:error] [pid 7148:tid 7189] [client 136.69.156.39:56238] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arthansl.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arthansl.com"] [uri "/z9x8c7v6b5-debug-trigger-arthansl.com"] [unique_id "arx6xPKJbtdfFL3JAUAbbwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-30 02:34:32
(1 day ago)
1.239 requests with url.path *.env
495 requests with url.path */@fs/*
162 requests with url.path ...
show more
1.239 requests with url.path *.env
495 requests with url.path */@fs/*
162 requests with url.path */proc/*
106 requests with url.path *.aws/*
101 requests with url.path *credentials.json
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
WizardsToolkit
2026-09-30 01:57:03
(1 day ago)
attempted to access /@fs/app/.env?raw??
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-30 01:48:54
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php
UA: Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
stinpriza
2026-09-30 01:45:01
(1 day ago)
common Web Exploits being scanned
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 01:03:45
(1 day ago)
[ti-09al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-09al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 136.69.156.39 - - [30/Sep/2026:03:03:33 +0200] "POST /lib/terminal-xhr.php HTTP/2.0" 404 6628 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
136.69.156.39 - - [30/Sep/2026:03:03:33 +0200] "GET /xpigci000daq3jivn48s HTTP/2.0" 404 6637 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
136.69.156.39 - - [30/Sep/2026:03:03:33 +0200] "GET /dz5zk31wxxokmfwgoywp HTTP/2.0" 404 6628 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
136.69.156.39 - - [30/Sep/2026:03:03:33 +0200] "GET /webpack-stats.json HTTP/2.0" 404 6628 "-" "Moz
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-30 00:24:02
(2 days ago)
Bad behaviour
Web Spam
๐บ๐ธ
TPI-Abuse
2026-09-30 00:15:56
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.69.156.39 (39.156.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.156.39 (39.156.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:15:50.449012 2026] [security2:error] [pid 11009:tid 11009] [client 136.69.156.39:35836] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arsenalfordemocracy.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arsenalfordemocracy.com"] [uri "/z9x8c7v6b5-debug-trigger-arsenalfordemocracy.com"] [unique_id "arxUtkFXjSmk1NC5VG7r0gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:52:16
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.69.156.39 (39.156.69.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.69.156.39 (39.156.69.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:52:12.399876 2026] [security2:error] [pid 7691:tid 7786] [client 136.69.156.39:54606] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||asetiadi.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "asetiadi.net"] [uri "/rclone.conf"] [unique_id "arxPLIc6lrIlLyzUdtMbGwAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack