๐บ๐ธ
TPI-Abuse
2026-09-30 04:58:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.232.10 (10.232.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.232.10 (10.232.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:58:12.404857 2026] [security2:error] [pid 7152:tid 7152] [client 34.39.232.10:52502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boyt.org"] [uri "/web.config"] [unique_id "aryW5CjqSr8O8zRb3baQIgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-09-30 04:28:24
(1 day ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/env/aws_credenti ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/env/aws_credentials.env via rule: /config
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
phoenix1jl96
2026-09-30 04:22:26
(1 day ago)
2026/09/30 06:22:25 [error] 3302796#3302796: *373357 open() "/home/user-data/www/default/cgi-bin/php ...
show more
2026/09/30 06:22:25 [error] 3302796#3302796: *373357 open() "/home/user-data/www/default/cgi-bin/php-cgi.exe" failed (2: No such file or directory), client: 34.39.232.10, server: box.ledemon.us, request: "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "calendar.ledemon.us"
2026/09/30 06:22:25 [error] 3302796#3302796: *373357 open() "/home/user-data/www/default/cgi-bin/php" failed (2: No such file or directory), client: 34.39.232.10, server: box.ledemon.us, request: "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "calendar.ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-30 04:18:51
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from BR.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from BR.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /login
UA: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ช
cmbplf
2026-09-30 03:59:40
(1 day ago)
2.940 requests from abuseipdb.com blacklisted IP (2mos3w2d)
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-09-30 03:55:23
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
masterguru
2026-09-30 03:52:44
(1 day ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 03:18:12
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.39.232.10 (10.232.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.232.10 (10.232.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:18:07.957464 2026] [security2:error] [pid 11692:tid 11692] [client 34.39.232.10:40226] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boudousquieart.armadillosigns.com|F|2"] [data ".armadillosigns.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boudousquieart.armadillosigns.com"] [uri "/z9x8c7v6b5-debug-trigger-boudousquieart.armadillosigns.com"] [unique_id "arx_b7WHJGXEmnfV-aqTSAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:58:47
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.39.232.10 (10.232.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.232.10 (10.232.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:58:41.453147 2026] [security2:error] [pid 9518:tid 9518] [client 34.39.232.10:47190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brightspine.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brightspine.com"] [uri "/z9x8c7v6b5-debug-trigger-brightspine.com"] [unique_id "arxewRCgAIQ1saymeh38ZwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hary74656
2026-09-29 23:51:36
(1 day ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
nd_anoma ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
nd_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "weavernet.at"] [uri "/login"] [unique_id "arxPB4QEtwJSvhqfWUJwSwAAkg8"]
[Wed Sep 30 01:51:35.706647 2026] [vhost aschi.at] [security2:error] [pid 356757:tid 140108860462784] [client 34.39.232.10:40834] [realclient 34.39.232.10:40834] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "weavernet.at"] [uri "/app-config.json"] [unique_id "arxPB4QEtwJSvhqfWUJwUQAAigg"]
show less
Web App Attack
๐ง๐ท
radardatelecom
2026-09-29 22:26:03
(1 day ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 22:02:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.39.232.10 (10.232.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.232.10 (10.232.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:02:07.825518 2026] [security2:error] [pid 31646:tid 31646] [client 34.39.232.10:43178] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brexitop.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brexitop.com"] [uri "/z9x8c7v6b5-debug-trigger-brexitop.com"] [unique_id "arw1X2kM1sNh0GSyQMh3qwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-29 20:37:56
(2 days ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-29T20:37:54.743089177Z. Context: http_status=200
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:26:30
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.39.232.10 (10.232.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.232.10 (10.232.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:26:24.625597 2026] [security2:error] [pid 18964:tid 18964] [client 34.39.232.10:53282] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bridgenevercrossed.banis-associates.com|F|2"] [data ".banis-associates.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bridgenevercrossed.banis-associates.com"] [uri "/z9x8c7v6b5-debug-trigger-bridgenevercrossed.banis-associates.com"] [unique_id "arwe8N4T65A7OfuXzmz20gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-09-29 20:11:04
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack