Anonymous
2026-09-12 09:21:02
(1 hour ago)
Bot / scanning and/or hacking attempts: GET /_profiler/open HTTP/2.0, GET /app_dev.php/_profiler HTT ...
show more
Bot / scanning and/or hacking attempts: GET /_profiler/open HTTP/2.0, GET /app_dev.php/_profiler HTTP/2.0, GET /config/firebase-admin.json HTTP/2.0, GET /app_dev.php HTTP/2.0, GET /_profiler/latest HTTP/2.0, GET /console HTTP/2.0, GET /.env.js HTTP/2.0, GET /server-info HTTP/2.0, GET /__debug__/ HTTP/2.0, GET /nginx_status HTTP/2.0
show less
Hacking
Web App Attack
🇩🇪
TheDjRider
2026-09-12 09:10:46
(1 hour ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-12T09:10:43.954418069Z. Context: http_status=200, http_status=404
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:09:07
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.11.162.234 (234.162.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.11.162.234 (234.162.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:09:01.606702 2026] [security2:error] [pid 965:tid 965] [client 34.11.162.234:34870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.braddonengineering.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqUWrYX2yutrCwzUAgymtAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
boxed-it
2026-09-12 03:52:15
(6 hours ago)
GET /config/.env (Tarpitted for 51m, wasted 179.41kB)
Web App Attack
🇧🇪
boxed-it
2026-09-11 20:14:32
(14 hours ago)
GET /console (Tarpitted for 26m21s, wasted 92.7kB)
Web App Attack
🇧🇪
brechtr
2026-09-11 18:45:01
(16 hours ago)
[Press84-BanHammer] 404 flood — 30 hits in 60s — Sourced from: brechtryckaert.com — Request: GET /i. ...
show more
[Press84-BanHammer] 404 flood — 30 hits in 60s — Sourced from: brechtryckaert.com — Request: GET /i.php
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:43:43
(16 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.11.162.234 (234.162.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.11.162.234 (234.162.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:43:39.005789 2026] [security2:error] [pid 15008:tid 15008] [client 34.11.162.234:39144] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||breathofgodministry.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "breathofgodministry.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqRL21zTvdMknCj9DUWhJwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:20:22
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.11.162.234 (234.162.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.11.162.234 (234.162.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:20:18.546086 2026] [security2:error] [pid 11730:tid 11730] [client 34.11.162.234:45100] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brazilianbikinis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brazilianbikinis.com"] [uri "/z9x8c7v6b5-debug-trigger-brazilianbikinis.com"] [unique_id "aqRGYs_Lbla0ipmncytlBQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alboweb B.V.
2026-09-11 18:11:07
(16 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
🇫🇮
as211431.net
2026-09-11 18:03:31
(16 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /api
UA: Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-11 17:58:01
(16 hours ago)
34.11.162.234 - - [11/Sep/2026:19:58:00 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; ...
show more
34.11.162.234 - - [11/Sep/2026:19:58:00 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
34.11.162.234 - - [11/Sep/2026:19:58:00 +0200] "GET /dashboard%2F.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.11.162.234 - - [11/Sep/2026:19:58:00 +0200] "GET /admin HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
34.11.162.234 - - [11/Sep/2026:19:58:00 +0200] "GET /settings%2F.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.11.162.234 - - [11/Sep/2026:19:58:00 +0200] "GET /user/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
34.11.162.234 - - [11/Sep/2026:19:58:00 +
...
show less
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-11 17:54:11
(16 hours ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
🇺🇸
[email protected]
2026-09-11 17:45:02
(17 hours ago)
CrowdSec ban: crowdsecurity/http-admin-interface-probing (duration: 71h59m53s)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:40:53
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.11.162.234 (234.162.11.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.11.162.234 (234.162.11.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:40:47.883943 2026] [security2:error] [pid 6481:tid 6481] [client 34.11.162.234:46790] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brandoncomputergeeks.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brandoncomputergeeks.com"] [uri "/z9x8c7v6b5-debug-trigger-brandoncomputergeeks.com"] [unique_id "aqQ9H8Qtes-1kUokcq_yMQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 17:26:35
(17 hours ago)
git/env leak probe
Web App Attack