๐ซ๐ฎ
as211431.net
2026-09-30 18:12:51
(30 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 (POST method)
Endpoint: /lib/terminal-xhr.php
UA: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 15:27:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:27:03.982307 2026] [security2:error] [pid 18328:tid 18328] [client 34.158.78.244:38538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.yeejia.net"] [uri "/.htpasswd"] [unique_id "ar0qR9f8TH5hS3xCL-gclAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 14:57:28
(3 hours ago)
404 burst scanner detected by fail2ban
...
Web App Attack
๐ฎ๐น
ciccio diddo
2026-09-30 14:50:59
(3 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:42:03
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:41:58.232379 2026] [security2:error] [pid 26466:tid 26466] [client 34.158.78.244:56646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dwars.net"] [uri "/.env.js"] [unique_id "ar0ftl45Om_HiqKb8o6GkAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:26:15
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:26:10.797286 2026] [security2:error] [pid 18110:tid 18110] [client 34.158.78.244:38092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wingblade.net"] [uri "/.htpasswd"] [unique_id "ar0cAiCPB0kgXgah4EMGLwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-30 14:17:07
(4 hours ago)
{"level":"info","ts":1790777826.0765269,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790777826.0765269,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.158.78.244","remote_port":"59814","client_ip":"34.158.78.244","proto":"HTTP/2.0","method":"GET","host":"status.b-u-t.net","uri":"/model/info","headers":{"Accept":["*/*"],"Authorization":["REDACTED"],"User-Agent":["Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.b-u-t.net","ech":false}},"bytes_read":0,"user_id":"","duration":0.000149716,"size":0,"status":429,"resp_headers":{"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"],"Server":["Caddy"]}}
{"level":"info","ts":1790777826.0789766,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.158.78.244","remote_port":"59814","client_ip":"34.158.78.244","proto":"HTTP/2.0","method":"GET","host":
...
show less
DDoS Attack
Web App Attack
Anonymous
2026-09-30 13:10:02
(5 hours ago)
suspicious request in access.log
Web App Attack
๐จ๐ฆ
alexbfr
2026-09-30 13:09:02
(5 hours ago)
Fail2Ban report from nginx-bot-trap; automated HTTP honeypot detection.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:06:10
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:06:07.253613 2026] [security2:error] [pid 1059:tid 1059] [client 34.158.78.244:46408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acquivest.net"] [uri "/_image"] [unique_id "ar0JP1Be1OU4OyROkzPaIAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 12:54:07
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 12:49:28
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:49:20.664801 2026] [security2:error] [pid 29076:tid 29076] [client 34.158.78.244:41588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.abakada.net"] [uri "/.env.js"] [unique_id "ar0FUC6u2ylcfQjTKI2XaAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
clapper
2026-09-30 12:35:19
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.158.78.244 (244.78.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.158.78.244 (244.78.158.34.bc.googleusercontent.com): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 12:22:54
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:22:49.636960 2026] [security2:error] [pid 26221:tid 26221] [client 34.158.78.244:47550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intelligent-design.net"] [uri "/.env.js"] [unique_id "arz_GSoVZgNczuDxPUNpuwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:56:31
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.78.244 (244.78.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:56:25.715067 2026] [security2:error] [pid 31945:tid 31945] [client 34.158.78.244:57334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.axiomemail.net"] [uri "/files../.env"] [unique_id "arz46ccTkisEnhyMcbelggAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack