🇬🇧
pinguin
2026-09-06 17:24:58
(2 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /terraform.tfstate
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇳🇱
0xffffffff
2026-09-06 16:25:28
(3 hours ago)
[2026-09-06 19:25:26.711803] [authz_core:error] [pid 872467:tid 132048335873728] [client 34.145.61.1 ...
show more
[2026-09-06 19:25:26.711803] [authz_core:error] [pid 872467:tid 132048335873728] [client 34.145.61.160:58078] AH01630: client denied by server configuration: /var/www/*/static , error_notes:config-files , URI:'/static//home/user/.env'
[2026-09-06 19:25:26.743350] [authz_core:error] [pid 872467:tid 132048487114432] [client 34.145.61.160:58078] AH01630: client denied by server configuration: /var/www/*/static , error_notes:config-files , URI:'/static//app/.env'
[2026-09-06 19:25:26.825949] [authz_core:error] [pid 872467:tid 132048319055552] [client 34.145.61.160:58078] AH01630: client denied by server configuration: /var/www/*/.env , error_notes:config-files , URI:'/.//.env'
[2026-09-06 19:25:26.826491] [authz_core:error] [pid 872467:tid 132048478721728] [client 34.145.61.160:58078] AH01630: client denied by server configuration: /var/www/*/rclone.conf , error_notes:sensitive-files , URI:'/rclone.conf'
[2026-09-06 19:25:26.832808] [authz_core:error] [pid 872467:tid 132048369510080] [client 34.145.61.160:58078]
show less
Web App Attack
Bad Web Bot
🇧🇬
HighWay
2026-09-06 15:46:46
(3 hours ago)
34.145.61.160 - - [06/Sep/2026:15:46:38 +0000] "GET /.git/HEAD HTTP/1.1" 403 421 "-" "Mozilla/5.0 (c ...
show more
34.145.61.160 - - [06/Sep/2026:15:46:38 +0000] "GET /.git/HEAD HTTP/1.1" 403 421 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.145.61.160 - - [06/Sep/2026:15:46:39 +0000] "GET /.git/config HTTP/1.1" 403 4408 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.145.61.160 - - [06/Sep/2026:15:46:39 +0000] "GET /.env HTTP/1.1" 403 421 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 15:30:26
(4 hours ago)
34.145.61.160 - - [06/Sep/2026:11:30:26 -0400] "GET /application.properties HTTP/1.1" 401 703 "-" "M ...
show more
34.145.61.160 - - [06/Sep/2026:11:30:26 -0400] "GET /application.properties HTTP/1.1" 401 703 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
Web App Attack
SSH
🇫🇷
dynamix
2026-09-06 15:09:28
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:01:17
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.145.61.160 (160.61.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.145.61.160 (160.61.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:01:07.481473 2026] [security2:error] [pid 22096:tid 22096] [client 34.145.61.160:59164] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||protucaribe.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "protucaribe.com"] [uri "/z9x8c7v6b5-debug-trigger-protucaribe.com"] [unique_id "ap1yI6rw8sgcAba8SpcXkQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-06 10:59:20
(8 hours ago)
34.145.61.160 - - [06/Sep/2026:06:59:19 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 5798 "-" "Mozi ...
show more
34.145.61.160 - - [06/Sep/2026:06:59:19 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 5798 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
34.145.61.160 - - [06/Sep/2026:06:59:19 -0400] "GET /@fs/../.env?raw?? HTTP/1.1" 404 5798 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
34.145.61.160 - - [06/Sep/2026:06:59:19 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 5798 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇩🇪
big-cloud.nl
2026-09-06 10:22:28
(9 hours ago)
Try to access /.vscode/launch.json
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-06 09:52:23
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.145.61.160 (US/United States/160.61. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.145.61.160 (US/United States/160.61.145.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 09:45:57
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.145.61.160 (160.61.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.145.61.160 (160.61.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:45:53.093581 2026] [security2:error] [pid 377234:tid 377241] [client 34.145.61.160:52846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.property-management.company|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.property-management.company"] [uri "/rclone.conf"] [unique_id "ap02UcrP8XMvsEK1w1xc0AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
H24
2026-09-06 09:40:00
(9 hours ago)
/public/.env /config.php.bak /wp-config.php.bak /storage/.env /wp-config.php~ /wp/.env /wp-config.ph ...
show more
/public/.env /config.php.bak /wp-config.php.bak /storage/.env /wp-config.php~ /wp/.env /wp-config.php.swp /configuration.php.bak /.env.php.bak /wp-config.php.old
show less
Web App Attack
🇵🇱
strefapi_com
2026-09-06 09:27:39
(10 hours ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇩🇪
Guardian
2026-09-06 08:51:07
(10 hours ago)
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x10), Unauthorized attempt to ret ...
show more
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x10), Unauthorized attempt to retrieve configuration file
34.145.61.160 [06/Sep/2026:10:51:04 +0200] "GET / HTTP/1.1"
34.145.61.160 [06/Sep/2026:10:51:05 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1"
34.145.61.160 [06/Sep/2026:10:51:05 +0200] "GET /@fs/proc/self/cmdline?raw?? HTTP/1.1"
34.145.61.160 [06/Sep/2026:10:51:05 +0200] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/token?raw?? HTTP/1.1"
34.145.61.160 [06/Sep/2026:10:51:06 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/1.1"
34.145.61.160 [06/Sep/2026:10:51:06 +0200] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/ca.crt?raw?? HTTP/1.1"
34.145.61.160 [06/Sep/2026:10:51:06 +0200] "GET /z9x8c7v6b5-debug-trigger-staging.******.*** HTTP/1.1"
34.145.61.160 [06/Sep/2026:10:51:06 +0200] "GET /api/proc/self/environ HTTP/1.1"
34.145.61.160 [06/Sep/2026:10:51:07 +02
show less
Port Scan
Web App Attack
Anonymous
2026-09-06 08:24:59
(11 hours ago)
Aggressive web scan
Web App Attack
🇩🇪
MBombeck
2026-09-06 07:48:36
(11 hours ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack