🇫🇮
as211431.net
2026-09-06 04:16:28
(3 hours ago)
Triggered Cloudflare WAF (firewallCustom) from ES.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from ES.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /auth.json
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 02:56:18
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.175.167.58 (58.167.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.175.167.58 (58.167.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:56:14.320344 2026] [security2:error] [pid 5506:tid 5506] [client 34.175.167.58:45752] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||perissos.mx.kevinfranz.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "perissos.mx.kevinfranz.com"] [uri "/storage/logs/laravel.log"] [unique_id "apzWTmgIoC8RSYUT4pntpQAAAFw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
thesimonmanuel
2026-09-06 02:06:54
(6 hours ago)
34.175.167.58 - - [06/Sep/2026:07:36:53 +0530] "GET /.env HTTP/1.1" 403 146 "-" "crusader-worker/1.0 ...
show more
34.175.167.58 - - [06/Sep/2026:07:36:53 +0530] "GET /.env HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
show less
Web App Attack
🇷🇴
SpamStopper
2026-09-06 02:02:09
(6 hours ago)
Fail2Ban - WordPress\(Anomis\) Looking for CMS/PHP/SQL vulnerabilities and hacked web hosts servers
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:22:30
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.167.58 (58.167.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.167.58 (58.167.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:22:23.238841 2026] [security2:error] [pid 20092:tid 20092] [client 34.175.167.58:45952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ktnwassociatesinc.com"] [uri "/.env.old"] [unique_id "apyyP8UnLSs1SWAAr0Gk8AAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-06 00:04:05
(8 hours ago)
Too many 404 requests [BY]
Web App Attack
🇩🇪
4server
2026-09-05 23:56:25
(8 hours ago)
[SunSep0601:56:22.0697542026][security2:error][pid2177322:tid2177399][client34.175.167.58:0]ModSecur ...
show more
[SunSep0601:56:22.0697542026][security2:error][pid2177322:tid2177399][client34.175.167.58:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"autoconfig.grigorov.ch\"][uri\"/.env.old\"][unique_id\"apysJvB9jMYeU6VBuAvifgAAAUA\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:54:05
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.167.58 (58.167.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.167.58 (58.167.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:01.765228 2026] [security2:error] [pid 5545:tid 5545] [client 34.175.167.58:33542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mjaaforum.org"] [uri "/.env.save"] [unique_id "apyrmdozUKwM0jl3v7xY0wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:27:29
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.167.58 (58.167.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.167.58 (58.167.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:27:25.453722 2026] [security2:error] [pid 9465:tid 9465] [client 34.175.167.58:33500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jaykaydrone.pics.krakowski.net"] [uri "/.env.dev"] [unique_id "apylXWchKJCUOy27Tdj7KQAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:07:54
(9 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.175.167.58 (58.167.175.34.bc.googleuserco ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.175.167.58 (58.167.175.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.175.167.58 - - [06/Sep/2026:01:07:52 +0200] "GET /.env.old HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
34.175.167.58 - - [06/Sep/2026:01:07:52 +0200] "GET /.env.backup HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.175.167.58 - - [06/Sep/2026:01:07:52 +0200] "GET /.env.bak HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
🇬🇧
consul.to
2026-09-05 23:04:25
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 23:00:21
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:32:30
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.167.58 (58.167.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.167.58 (58.167.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:32:26.798078 2026] [security2:error] [pid 18702:tid 18702] [client 34.175.167.58:40350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tmcbizdev.com"] [uri "/.env.local"] [unique_id "apyYejOPQJAMn4LG810UsAAAAHg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
DEV-DNS
2026-09-05 21:59:50
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-05 21:39:47
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.167.58 (58.167.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.167.58 (58.167.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:39:42.490687 2026] [security2:error] [pid 15516:tid 15516] [client 34.175.167.58:33638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.furryfriendzy.org"] [uri "/.env"] [unique_id "apyMHuOWvsaEaMzihV5nGwAAAHc"]
show less
Brute-Force
Bad Web Bot
Web App Attack