🇺🇸
TPI-Abuse
2026-09-07 02:53:18
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.156.221.25 (25.221.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.221.25 (25.221.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:53:14.548738 2026] [security2:error] [pid 1118580:tid 1118580] [client 34.156.221.25:58326] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cottrillcyclodyne.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cottrillcyclodyne.com"] [uri "/rclone.conf"] [unique_id "ap4nGoOZmTwK7U2xLTYYdAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 01:43:53
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
Savvii
2026-09-07 01:43:34
(6 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 00:27:06
(7 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 23:09:54
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.156.221.25 (25.221.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.221.25 (25.221.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:09:46.124961 2026] [security2:error] [pid 13760:tid 13760] [client 34.156.221.25:46274] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||d-sinema.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "d-sinema.com"] [uri "/z9x8c7v6b5-debug-trigger-d-sinema.com"] [unique_id "ap3yuu6UalBPJCowPBX8gAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
mrcrassi
2026-09-06 22:43:05
(9 hours ago)
Triggered Cloudflare WAF (firewallManaged) from BE.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from BE.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /@fs/.env
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 22:03:37
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.156.221.25 (25.221.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.221.25 (25.221.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:03:29.621721 2026] [security2:error] [pid 13627:tid 13627] [client 34.156.221.25:50058] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wurkroom.biz|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wurkroom.biz"] [uri "/rclone.conf"] [unique_id "ap3jMR030zbqkGRs2RaFMwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alboweb B.V.
2026-09-06 21:11:02
(10 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 20:37:32
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.221.25 (25.221.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.221.25 (25.221.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:37:27.971668 2026] [security2:error] [pid 30285:tid 30285] [client 34.156.221.25:35312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esquema-arch.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ap3PB29GwYW4XLz2f38Y0wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 20:35:14
(11 hours ago)
457 requests with url.path */@fs/*
167 requests with url.path *.oci/*
106 requests with url.path ...
show more
457 requests with url.path */@fs/*
167 requests with url.path *.oci/*
106 requests with url.path *.aws/*
show less
Brute-Force
Bad Web Bot
Anonymous
2026-09-06 19:56:03
(11 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 19:51:44
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.221.25 (25.221.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.221.25 (25.221.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:51:37.331104 2026] [security2:error] [pid 32178:tid 32178] [client 34.156.221.25:35014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hometechllc.com"] [uri "/static../.env"] [unique_id "ap3ESWR7TYmt7KUT1I1SCQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 19:12:00
(12 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:13:47
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.221.25 (25.221.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.221.25 (25.221.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:13:42.016616 2026] [security2:error] [pid 12525:tid 12525] [client 34.156.221.25:59534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weddingmusicguitar.com"] [uri "/.git/config"] [unique_id "ap2tVgLJgrRLIj7LLH-vuAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 17:36:32
(14 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking