🇫🇮
000rosiu
2026-09-12 19:39:11
(16 hours ago)
Triggered Cloudflare WAF (firewallCustom) from BR.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from BR.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /phpinfo.php.old | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇫🇷
LRNP
2026-09-12 19:34:27
(16 hours ago)
aime.lesmatric.es:443 34.151.207.236 - - [12/Sep/2026:19:34:27 +0000] "GET /.env HTTP/1.1" 404 181 " ...
show more
aime.lesmatric.es:443 34.151.207.236 - - [12/Sep/2026:19:34:27 +0000] "GET /.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇧🇷
dominioz
2026-09-12 19:21:26
(17 hours ago)
2026-09-12 19:20:43 GET /.env - - 34.151.207.236 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKi ...
show more
2026-09-12 19:20:43 GET /.env - - 34.151.207.236 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 559
2026-09-12 19:20:43 GET /.env.local - - 34.151.207.236 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 571
2026-09-12 19:20:43 GET /.env.production - - 34.151.207.236 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 581
2026-09-12 19:20:43 GET /.env.staging - - 34.151.207.236 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 575
2026-09-12 19:20:43 GET /.env.development - - 34.151.207.236 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 583
2026-09-12 19:20:43 GET /.env.test - - 34.151.207.236 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 17:25:02
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 13:24:55.071657 2026] [security2:error] [pid 13514:tid 13514] [client 34.151.207.236:39154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acquivest.net"] [uri "/.git/config"] [unique_id "aqWK55UhkwKXTCxPDZ5sHwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-12 16:23:58
(20 hours ago)
[SatSep1218:23:52.9174082026][security2:error][pid3422671:tid3422788][client34.151.207.236:0]ModSecu ...
show more
[SatSep1218:23:52.9174082026][security2:error][pid3422671:tid3422788][client34.151.207.236:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"acquaallaspina.ch.bluwater.ch\"][uri\"/\"][unique_id\"aqV8mBHI30J7dpAS1R7NowAAAE4\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 15:44:34
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 11:44:26.503478 2026] [security2:error] [pid 5410:tid 5410] [client 34.151.207.236:48158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acpalms.com"] [uri "/.git/config"] [unique_id "aqVzWvJpFoVa6ruqMcFrfgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Lee Daniel
2026-09-12 14:16:11
(22 hours ago)
34.151.207.236 - - [12/Sep/2026:10:16:11 -0400] "GET /.env HTTP/1.1" 403 6296 "-" "Mozilla/5.0 (Wind ...
show more
34.151.207.236 - - [12/Sep/2026:10:16:11 -0400] "GET /.env HTTP/1.1" 403 6296 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 14:01:03
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 10:00:55.961625 2026] [security2:error] [pid 10347:tid 10347] [client 34.151.207.236:43482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aiinlocal.com"] [uri "/.git/config"] [unique_id "aqVbFxOqSyQG3IDxYN6EzAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ipoac.nl
2026-09-12 12:53:39
(23 hours ago)
-:443 34.151.207.236 - - [12/Sep/2026:14:53:37 +0200] - "GET /.git/config HTTP/1.1" 404 1962 "-" "Mo ...
show more
-:443 34.151.207.236 - - [12/Sep/2026:14:53:37 +0200] - "GET /.git/config HTTP/1.1" 404 1962 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
🇬🇧
consul.to
2026-09-12 11:36:48
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:22:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:22:51.427618 2026] [security2:error] [pid 17992:tid 17992] [client 34.151.207.236:55226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acmeradar.com"] [uri "/.git/config"] [unique_id "aqU2Cw__V_KuWpvmT5K76gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:31:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:31:40.638225 2026] [security2:error] [pid 7597:tid 7597] [client 34.151.207.236:60804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aifstudio.com"] [uri "/.git/config"] [unique_id "aqUqDCPbnZT6gsaE-PgRagAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-12 09:30:36
(1 day ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
🇧🇪
FrankNeirynck
2026-09-12 09:25:15
(1 day ago)
aifebelco.ttl.be 34.151.207.236 - - [12/Sep/2026:11:25:13 +0200] "GET /.git/config HTTP/1.1" 404 196 ...
show more
aifebelco.ttl.be 34.151.207.236 - - [12/Sep/2026:11:25:13 +0200] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 0.000
aifebelco.ttl.be 34.151.207.236 - - [12/Sep/2026:11:25:13 +0200] "GET /.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 0.000
aifebelco.ttl.be 34.151.207.236 - - [12/Sep/2026:11:25:14 +0200] "GET /.env.local HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 0.000
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 08:49:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.207.236 (236.207.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:49:10.643070 2026] [security2:error] [pid 2824:tid 2856] [client 34.151.207.236:46142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aclarityforensics.com"] [uri "/.git/config"] [unique_id "aqUSBmK4WFiGL06DOv2kigAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack