๐ง๐ท
leonan
2026-08-21 14:59:46
(1 hour ago)
(cpanel) Failed cPanel login from 34.139.116.198 (US/United States/198.116.139.34.bc.googleuserconte ...
show more
(cpanel) Failed cPanel login from 34.139.116.198 (US/United States/198.116.139.34.bc.googleusercontent.com): 50 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CPANEL; Logs: [2026-08-21 11:59:39 -0300] info [webmaild] 34.139.116.198 - - "GET /__/firebase/init.json HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-08-21 11:59:40 -0300] info [webmaild] 34.139.116.198 - - "GET /private-key HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-08-21 11:59:40 -0300] info [webmaild] 34.139.116.198 - - "GET /.env HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-08-21 11:59:40 -0300] info [webmaild] 34.139.116.198 - - "GET /z9x8c7v6b5-debug-trigger-webmail.praiasitaipu.com.br HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-08-21 11:59:40 -0300] info [webmaild] 34.139.116.198 - - "GET /config.json HTTP/1.1" FAILED LOGIN webmaild: login attempt without username
[2026-08-21 11:59:40 -0300] info [webmaild [truncated]
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-21 14:04:42
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 10:04:34.108144 2026] [security2:error] [pid 14580:tid 14580] [client 34.139.116.198:47384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ozmosis.net"] [uri "/.git/HEAD"] [unique_id "aoha8vNvi3QHrcLz83PHsAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 12:52:52
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 08:52:45.288435 2026] [security2:error] [pid 19032:tid 19032] [client 34.139.116.198:51350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.martinka.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.martinka.org"] [uri "/rclone.conf"] [unique_id "aohKHU_J7bxBiE_PzlYokwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 12:27:25
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 08:27:19.106243 2026] [security2:error] [pid 20312:tid 20312] [client 34.139.116.198:43490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.liddlesports.com"] [uri "/.git/config"] [unique_id "aohEJ8UxE0DyQjMxdBfVXwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CBJ
2026-08-21 11:54:33
(4 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐ฉ๐ช
bazter.pro
2026-08-21 10:01:26
(6 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 09:57:33
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 05:57:25.696543 2026] [security2:error] [pid 7111:tid 7111] [client 34.139.116.198:52998] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.galaxyretro.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.galaxyretro.com"] [uri "/rclone.conf"] [unique_id "aoghBSu89dELLBy5s4cvFQAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 09:12:08
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 05:12:00.242728 2026] [security2:error] [pid 23577:tid 23577] [client 34.139.116.198:42218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.danged.com"] [uri "/config/.env"] [unique_id "aogWYFVMI589_QF_1FuG_AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-21 09:08:48
(6 hours ago)
apache vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 08:56:37
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 04:56:30.758721 2026] [security2:error] [pid 11772:tid 11772] [client 34.139.116.198:51546] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.circlehealthcaregroup.com|F|2"] [data ".circlehealthcaregroup.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.circlehealthcaregroup.com"] [uri "/z9x8c7v6b5-debug-trigger-www.circlehealthcaregroup.com"] [unique_id "aogSvs7lASc61uK1_xSuKAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-21 08:20:26
(7 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /application.yml
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-21 08:19:52
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 04:19:47.779576 2026] [security2:error] [pid 21028:tid 21028] [client 34.139.116.198:36460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aticom.es"] [uri "/production/.env"] [unique_id "aogKI6wS6QhY-GDEiXJ80gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-21 08:15:16
(7 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.139.116.198 (US/United States/198.116 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.139.116.198 (US/United States/198.116.139.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.139.116.198 - - [21/Aug/2026:10:15:15 +0200] "GET /secrets.yml HTTP/2.0" 429 41 "-" "Mozilla/5.0 (compatible; Google-Agent; +http://www.google.com/bot.html)" "-" host=www.arkon.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-21 07:57:12
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 03:57:07.566166 2026] [security2:error] [pid 8305:tid 8358] [client 34.139.116.198:39868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manage.aafm.us"] [uri "/.git/config"] [unique_id "aogE067OrG-RgleCrmKZtwAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 06:31:51
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.116.198 (198.116.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 02:31:47.594159 2026] [security2:error] [pid 10595:tid 10595] [client 34.139.116.198:47796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ryanc.net"] [uri "/.git/config"] [unique_id "aofw0xxyzRL0xwf0Ny-AyQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack