πΏπ¦
conure.sh
2026-10-01 12:07:53
(3 days ago)
csagent: score 20.9: 404 noise floor x44, secrets grab x1; 1 domain(s) in 1s
Web App Attack
π«π·
masterguru
2026-10-01 07:03:58
(3 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-01 06:15:07
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.52.134.69 (69.134.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.52.134.69 (69.134.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:15:01.211256 2026] [security2:error] [pid 18310:tid 18310] [client 34.52.134.69:38024] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.angelpalomino.com|F|2"] [data ".angelpalomino.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.angelpalomino.com"] [uri "/z9x8c7v6b5-debug-trigger-www.angelpalomino.com"] [unique_id "ar36ZdF-dOknJDsuiMEmUwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 05:42:57
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.52.134.69 (69.134.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.52.134.69 (69.134.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:42:51.299297 2026] [security2:error] [pid 10741:tid 10741] [client 34.52.134.69:50708] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||antcanada.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "antcanada.com"] [uri "/z9x8c7v6b5-debug-trigger-antcanada.com"] [unique_id "ar3y2z9hKv1YoFrXus9rvQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
itsolon
2026-10-01 05:11:52
(3 days ago)
[01/Oct/2026:07:11:51 +0200] 179083151157.966201 34.52.134.69 0 217.154.7.177 443
[01/Oct/2026:07:11 ...
show more
[01/Oct/2026:07:11:51 +0200] 179083151157.966201 34.52.134.69 0 217.154.7.177 443
[01/Oct/2026:07:11:51 +0200] 17908315113.877375 34.52.134.69 0 217.154.7.177 443
[01/Oct/2026:07:11:51 +0200] 179083151183.301771 34.52.134.69 0 217.154.7.177 443
[01/Oct/2026:07:11:51 +0200] 179083151129.674236 34.52.134.69 0 217.154.7.177 443
[01/Oct/2026:07:11:51 +0200] 179083151150.829826 34.52.134.69 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π©πͺ
macrob
2026-10-01 03:38:00
(3 days ago)
2026/10/01 03:37:59 [error] 1578993#1578993: *3379480 access forbidden by rule, client: 34.52.134.69 ...
show more
2026/10/01 03:37:59 [error] 1578993#1578993: *3379480 access forbidden by rule, client: 34.52.134.69, server: antzfund.com, request: "GET /.ssh/config HTTP/1.1", host: "www.antzfund.com"
2026/10/01 03:37:59 [error] 1578994#1578994: *3379510 access forbidden by rule, client: 34.52.134.69, server: antzfund.com, request: "GET /.bashrc HTTP/1.1", host: "www.antzfund.com"
2026/10/01 03:37:59 [error] 1578994#1578994: *3379508 access forbidden by rule, client: 34.52.134.69, server: antzfund.com, request: "GET /@fs/src/.env?raw?? HTTP/1.1", host: "www.antzfund.com"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 03:22:39
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.52.134.69 (69.134.52.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.52.134.69 (69.134.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:22:34.966938 2026] [security2:error] [pid 9734:tid 10135] [client 34.52.134.69:56600] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anthonydalessandro.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anthonydalessandro.com"] [uri "/z9x8c7v6b5-debug-trigger-anthonydalessandro.com"] [unique_id "ar3R-lummIfII6loyhNtRwAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
1gz
2026-10-01 03:20:10
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /firebase-config.json
UA: DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π©πͺ
paissangroup
2026-10-01 00:39:39
(3 days ago)
Multiple WAF Violations
Web App Attack
π³π±
Site.eu
2026-09-30 23:17:27
(3 days ago)
Excessive multi-domain requests
Brute-Force
π§π·
radardatelecom
2026-09-30 22:26:04
(3 days ago)
Blocked by Radar da Telecom firewall β abuseipdb
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-09-30 21:53:35
(3 days ago)
636 requests with url.path *.env
187 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
πΊπΈ
drewking
2026-09-30 18:35:59
(3 days ago)
Rate-limit abuse β 60 requests in a short window (brute-force / scraping). Targeted paths: /.ssh/id_ ...
show more
Rate-limit abuse β 60 requests in a short window (brute-force / scraping). Targeted paths: /.ssh/id_rsa, /sa.json, /@fs/proc/self/cmdline?raw??, /firebase-credentials.json, /userfiles?path=../../../../proc/self/environ.
show less
Web App Attack
Brute-Force
Bad Web Bot
πͺπΈ
robotstxt
2026-09-30 17:36:42
(3 days ago)
34.52.134.69 - - [30/Sep/2026:17:36:32 +0000] "GET /.gitlab-ci.yml HTTP/2.0" 403 49525 "-" "Mozilla/ ...
show more
34.52.134.69 - - [30/Sep/2026:17:36:32 +0000] "GET /.gitlab-ci.yml HTTP/2.0" 403 49525 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-"
34.52.134.69 - - [30/Sep/2026:17:36:32 +0000] "GET /.github/workflows/deploy.yml HTTP/2.0" 403 49595 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-"
34.52.134.69 - - [30/Sep/2026:17:36:37 +0000] "GET /.npmrc HTTP/2.0" 403 49587 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-"
34.52.134.69 - - [30/Sep/2026:17:36:37 +0000] "GET /.htpasswd HTTP/2.0" 403 49577 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-"
34.52.134.69 - - [30/Sep/2026:17:36:37 +0000] "GET /.ssh/id_rsa HTTP/2.0" 403 49530 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-"
...
show less
Web App Attack
π¬π§
Swiptly
2026-09-30 17:04:45
(3 days ago)
Excessive 403/404/405 PHP/CMS errors from scanning or broken bots
...
Web App Attack