🇲🇾
Rizzy
2026-09-07 02:26:53
(58 minutes ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
mnsf
2026-09-07 02:05:16
(1 hour ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 00:59:47
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.85.120.4 (4.120.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.85.120.4 (4.120.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:59:43.122944 2026] [security2:error] [pid 9665:tid 9665] [client 136.85.120.4:33784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||coffeewitheinstein.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "coffeewitheinstein.com"] [uri "/z9x8c7v6b5-debug-trigger-coffeewitheinstein.com"] [unique_id "ap4Mf98zYMRH95cGy0Jw9AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-07 00:46:08
(2 hours ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /wp-config.php~
UA: Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
Philister11
2026-09-07 00:21:24
(3 hours ago)
CrowdSec: crowdsecurity/http-crawl-non_statics (US/AS396982)
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 22:03:59
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
london2038.com
2026-09-06 20:54:46
(6 hours ago)
Probing for exploits
136.85.120.4 - - [06/Sep/2026:22:54:42 +0200] "GET /@fs/home/ubuntu/.aws/creden ...
show more
Probing for exploits
136.85.120.4 - - [06/Sep/2026:22:54:42 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2.0" 422 0 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
136.85.120.4 - - [06/Sep/2026:22:54:42 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/2.0" 422 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
show less
Hacking
Web App Attack
🇺🇸
WellSpring
2026-09-06 20:51:48
(6 hours ago)
env leak on 203.today/static/app/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇧🇪
cmbplf
2026-09-06 20:49:00
(6 hours ago)
114 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 20:30:01
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.85.120.4 (4.120.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.85.120.4 (4.120.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:29:56.653418 2026] [security2:error] [pid 30731:tid 30731] [client 136.85.120.4:58636] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||streetcarz.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "streetcarz.net"] [uri "/rclone.conf"] [unique_id "ap3NRD1mur8Nq8MiBffdCgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Niko's Stuff
2026-09-06 20:15:41
(7 hours ago)
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/136.85.120.4
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 19:51:30
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.85.120.4 (4.120.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.85.120.4 (4.120.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:51:23.701943 2026] [security2:error] [pid 13008:tid 13008] [client 136.85.120.4:41348] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bikiniwatersports.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bikiniwatersports.com"] [uri "/z9x8c7v6b5-debug-trigger-bikiniwatersports.com"] [unique_id "ap3EO-Pz5nG642VPQ35FiAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 19:32:22
(7 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 19:06:14
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-06 18:53:43
(8 hours ago)
Multiple WAF Violations
Web App Attack