🇳🇱
e.fierstra
2026-09-13 01:16:46
(17 minutes ago)
excessive HTTP 404 errors
Bad Web Bot
🇺🇸
lavnet.net
2026-09-13 01:13:25
(20 minutes ago)
34.21.80.87 - - [13/Sep/2026:01:13:25 +0000] "GET /..%2f.env HTTP/2.0" 404 1901 "-" "Mozilla/5.0 (co ...
show more
34.21.80.87 - - [13/Sep/2026:01:13:25 +0000] "GET /..%2f.env HTTP/2.0" 404 1901 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
34.21.80.87 - - [13/Sep/2026:01:13:25 +0000] "GET /%2e%2e/.env HTTP/2.0" 400 1841 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
34.21.80.87 - - [13/Sep/2026:01:13:25 +0000] "GET /login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0"
34.21.80.87 - - [13/Sep/2026:01:13:25 +0000] "GET /z9x8c7v6b5-debug-trigger-jackaltx.com HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.21.80.87 - - [13/Sep/2026:01:13:25 +0000] "GET /api/.env/public/.env HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.21.80.87 - - [13/Sep/2026:01:13:25 +0000] "GET /..%2f..%2f.env HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; D
...
show less
Brute-Force
🇷🇺
DZBOT
2026-09-13 01:08:54
(25 minutes ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇬🇧
andypiper
2026-09-13 01:02:33
(31 minutes ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 01:00:50
(33 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.21.80.87 (87.80.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.21.80.87 (87.80.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:00:43.315205 2026] [security2:error] [pid 25225:tid 25225] [client 34.21.80.87:47974] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jabbosjingles.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jabbosjingles.com"] [uri "/z9x8c7v6b5-debug-trigger-jabbosjingles.com"] [unique_id "aqX1u3aQm66zj5N-K-3HqgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 00:21:17
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.21.80.87 (87.80.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.80.87 (87.80.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:21:10.862913 2026] [security2:error] [pid 806:tid 806] [client 34.21.80.87:60902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iyp-home.com"] [uri "/static//.env"] [unique_id "aqXsdiJMTehTrHOqi5zlzgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-13 00:12:00
(1 hour ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /api
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-13 00:10:02
(1 hour ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
🇪🇸
masterguru
2026-09-13 00:03:09
(1 hour ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:user-agent. (1100000-122)
Bad Web Bot
🇩🇪
FD-IX
2026-09-12 23:45:55
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 23:42:03
(1 hour ago)
34.21.80.87 - - [12/Sep/2026:23:42:01 +0000] "GET /.ssh/config HTTP/2.0" 301 162 "-" "Mozilla/5.0 ( ...
show more
34.21.80.87 - - [12/Sep/2026:23:42:01 +0000] "GET /.ssh/config HTTP/2.0" 301 162 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "34.21.80.87" "-"
...
show less
Web App Attack
🇳🇱
Savvii
2026-09-12 23:41:33
(1 hour ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-12 23:16:11
(2 hours ago)
80,443
Brute-Force
SSH
🇳🇱
i-turnradio.nl
2026-09-12 23:07:29
(2 hours ago)
2026-09-13 @ 01:07:23 (CET) ~ Blocked for trying to access: /var/run/secrets/kubernetes.io/serviceac ...
show more
2026-09-13 @ 01:07:23 (CET) ~ Blocked for trying to access: /var/run/secrets/kubernetes.io/serviceaccount/token
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:00:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.80.87 (87.80.21.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.80.87 (87.80.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:00:50.638539 2026] [security2:error] [pid 4571:tid 4571] [client 34.21.80.87:47504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "itsupitsdown.com"] [uri "/@fs/../.env"] [unique_id "aqXZoizH6kJNfI3z_JNjlwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack