Anonymous
2026-09-24 00:03:45
(1 minute ago)
Wordpress vulnerability scanning
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 23:08:34
(56 minutes ago)
(mod_security) mod_security (id:210730) triggered by 34.40.78.19 (19.78.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.40.78.19 (19.78.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 19:08:28.404585 2026] [security2:error] [pid 8242:tid 8242] [client 34.40.78.19:51566] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.albioncapitalfund.com|F|2"] [data ".albioncapitalfund.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.albioncapitalfund.com"] [uri "/z9x8c7v6b5-debug-trigger-www.albioncapitalfund.com"] [unique_id "arRb7Aym5dW9Z3K5pM6F4AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-23 22:23:57
(1 hour ago)
Brute-Force
Web App Attack
๐ซ๐ท
Zundapper
2026-09-23 20:09:55
(3 hours ago)
34.40.78.19 - - [23/Sep/2026:22:09:55 +0200] "GET /login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; ...
show more
34.40.78.19 - - [23/Sep/2026:22:09:55 +0200] "GET /login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.40.78.19 - - [23/Sep/2026:22:09:55 +0200] "GET /auth HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.40.78.19 - - [23/Sep/2026:22:09:55 +0200] "GET /sign-in HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
34.40.78.19 - - [23/Sep/2026:22:09:55 +0200] "GET /z9x8c7v6b5-debug-trigger-airsanit.com HTTP/2.0" 404 106 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
34.40.78.19 - - [23/Sep/2026:22:09:55 +0200] "GET /cxhhcyq327e498pmuvly HTTP/2.0" 404 106 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
Port Scan
๐จ๐ฆ
john doe
2026-09-23 20:00:57
(4 hours ago)
SentinelBot: Env File Hunting, Backup File Hunt (score: 73)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-23 19:42:42
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.40.78.19 (19.78.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.40.78.19 (19.78.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:42:36.972413 2026] [security2:error] [pid 10999:tid 10999] [client 34.40.78.19:40792] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aivosminerals.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aivosminerals.com"] [uri "/z9x8c7v6b5-debug-trigger-aivosminerals.com"] [unique_id "arQrrMHKO4qrS6NFe68y5AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 19:31:03
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:18:02
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.40.78.19 (19.78.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.40.78.19 (19.78.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:17:57.526037 2026] [security2:error] [pid 28280:tid 28280] [client 34.40.78.19:49698] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ajvaage.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ajvaage.com"] [uri "/z9x8c7v6b5-debug-trigger-ajvaage.com"] [unique_id "arQl5ZlXfvLHlxkAaMnbbgAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-23 19:05:02
(5 hours ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:54:41
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.40.78.19 (19.78.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:949110) triggered by 34.40.78.19 (19.78.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:54:37.661917 2026] [security2:error] [pid 7601:tid 7601] [client 34.40.78.19:39664] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "akistech.com"] [uri "/z9x8c7v6b5-debug-trigger-akistech.com"] [unique_id "arQgbfqv8cQTa1q5gtKNjAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-09-23 18:44:39
(5 hours ago)
tried to access forbidden files; attempted to access /storage/logs/laravel.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:06:59
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.40.78.19 (19.78.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.40.78.19 (19.78.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:06:54.502934 2026] [security2:error] [pid 8052:tid 8052] [client 34.40.78.19:49486] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alanrmariotti.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alanrmariotti.com"] [uri "/z9x8c7v6b5-debug-trigger-alanrmariotti.com"] [unique_id "arQVPnfEvMUcFHMhA5A_2gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
1gz
2026-09-23 17:44:16
(6 hours ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /script.js
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ฎ
albionfreemarket.com
2026-09-23 17:43:12
(6 hours ago)
34.40.78.19 - - [23/Sep/2026:17:43:10 +0000] "POST /graphql HTTP/2.0" 403 555 "https://albionfreemar ...
show more
34.40.78.19 - - [23/Sep/2026:17:43:10 +0000] "POST /graphql HTTP/2.0" 403 555 "https://albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "DE"
34.40.78.19 - - [23/Sep/2026:17:43:10 +0000] "POST /api/graphql HTTP/2.0" 403 555 "https://albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "DE"
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
elcruzado.es
2026-09-23 17:42:07
(6 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.40.78.19 (DE/Germ ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.40.78.19 (DE/Germany/19.78.40.34.bc.googleusercontent.com)
show less
Bad Web Bot