🇲🇾
Rizzy
2026-09-12 16:01:09
(1 hour ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 15:09:27
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.4.121 (121.4.35.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.4.121 (121.4.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 11:09:20.431646 2026] [security2:error] [pid 6360:tid 6360] [client 34.35.4.121:37532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nvafc.com"] [uri "/.git/config"] [unique_id "aqVrIDKRfhXhDJ5jIawPYAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-12 14:40:39
(3 hours ago)
[12/Sep/2026:17:40:38 +0300] -- 34.35.4.121 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/c ...
show more
[12/Sep/2026:17:40:38 +0300] -- 34.35.4.121 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
etu brutus
2026-09-12 11:50:54
(5 hours ago)
34.35.4.121 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-12 11:26:39
(6 hours ago)
8.455 requests with url.path *.env
1.508 requests with url.path *phpinfo.php
255 requests with ur ...
show more
8.455 requests with url.path *.env
1.508 requests with url.path *phpinfo.php
255 requests with url.path *credentials.json
show less
Brute-Force
Bad Web Bot
🇫🇮
as211431.net
2026-09-12 11:00:54
(6 hours ago)
Triggered Cloudflare WAF (linkMaze) from ZA.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from ZA.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 10:34:49
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.4.121 (121.4.35.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.4.121 (121.4.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:34:42.086844 2026] [security2:error] [pid 11138:tid 11138] [client 34.35.4.121:35472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nutshell.tag-scaffolding.com"] [uri "/.git/config"] [unique_id "aqUqwsftAjBmxA7seb_2MwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇯🇵
ki3
2026-09-12 10:25:06
(7 hours ago)
Fail2Ban: Web App Attacks and Forum Spam 34.35.4.121 1789208705.0(JST)
Web Spam
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-12 09:05:02
(8 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 07:00:43
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.4.121 (121.4.35.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.4.121 (121.4.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:00:39.255829 2026] [security2:error] [pid 3908:tid 3908] [client 34.35.4.121:33964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "og.gmacguffin.com"] [uri "/.git/config"] [unique_id "aqT4lwUT3W2Y2pQGr9_mhAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
robotstxt
2026-09-12 06:34:58
(11 hours ago)
34.35.4.121 - - [12/Sep/2026:06:33:46 +0000] "POST / HTTP/1.1" 403 11897 "-" "Mozilla/5.0 (X11; Linu ...
show more
34.35.4.121 - - [12/Sep/2026:06:33:46 +0000] "POST / HTTP/1.1" 403 11897 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.35.4.121"
34.35.4.121 - - [12/Sep/2026:06:33:47 +0000] "POST / HTTP/1.1" 403 11897 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.35.4.121"
34.35.4.121 - - [12/Sep/2026:06:33:47 +0000] "GET /.git/config HTTP/1.1" 403 12025 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.35.4.121"
34.35.4.121 - - [12/Sep/2026:06:33:48 +0000] "GET /.env HTTP/1.1" 403 12025 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.35.4.121"
34.35.4.121 - - [12/Sep/2026:06:33:48 +0000] "GET /.env.local HTTP/1.1" 403 12025 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 05:49:19
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.4.121 (121.4.35.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.4.121 (121.4.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:49:11.619700 2026] [security2:error] [pid 21864:tid 21888] [client 34.35.4.121:35960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oftv.xyz"] [uri "/.git/config"] [unique_id "aqTn1__SHrLeGi7tXQvCewAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-12 05:15:21
(12 hours ago)
Multiple WAF Violations
Web App Attack
🇪🇸
scaballe
2026-09-12 05:13:14
(12 hours ago)
Web App Attack
Anonymous
2026-09-12 04:37:54
(13 hours ago)
Web application attack detected.
Web App Attack