Anonymous
2026-09-07 02:11:12
(12 hours ago)
apache vulnerability scan
Web App Attack
🇬🇧
andypiper
2026-09-07 01:00:45
(13 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
Anonymous
2026-09-07 00:56:05
(13 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 00:15:31
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.231.183 (183.231.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.231.183 (183.231.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:15:24.848628 2026] [security2:error] [pid 8151:tid 8151] [client 34.61.231.183:50530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marlinlee.com"] [uri "/_nuxt/../.env"] [unique_id "ap4CHCyHykg4HkLH-SPF0AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 23:54:43
(14 hours ago)
Automatically blocked after 9 security events. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 9 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-06 19:43:01
(18 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇫🇮
as211431.net
2026-09-06 18:27:59
(20 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /info.php
UA: Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 18:03:11
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.231.183 (183.231.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.231.183 (183.231.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:03:05.944710 2026] [security2:error] [pid 25752:tid 25752] [client 34.61.231.183:38556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "admin.cmabiblequizzing.org"] [uri "/%2e%2e/.env"] [unique_id "ap2q2dK0RhcDLPVo5i3YpQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Mediashaker
2026-09-06 16:49:17
(21 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.61.231.183 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.61.231.183 (US/United States/183.231.61.34.bc.googleusercontent.com)
show less
Bad Web Bot
Anonymous
2026-09-06 16:28:14
(22 hours ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /firebase-adminsdk.json
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:39:20
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.61.231.183 (183.231.61.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.61.231.183 (183.231.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:39:16.456715 2026] [security2:error] [pid 31943:tid 31943] [client 34.61.231.183:43828] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hardcountryrock.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hardcountryrock.com"] [uri "/ssl/localhost.key"] [unique_id "ap2JJE6FRedV92J7wmFLawAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
abuse-detection
2026-09-06 14:36:56
(23 hours ago)
Web security detection (random-404-web-probe); path=/register; status=404
Bad Web Bot
🇩🇪
maxpower
2026-09-06 14:00:57
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.61.231.183 (US/United States/183.231. ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.61.231.183 (US/United States/183.231.61.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.61.231.183 - - [06/Sep/2026:16:00:54 +0200] "GET /config/secrets.yml HTTP/2.0" 200 4716 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" "34.61.231.183" host=lidotrocadero.com
show less
Port Scan
🇨🇭
ALPHANET
2026-09-06 13:47:45
(1 day ago)
web exploits
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-06 13:45:27
(1 day ago)
Observed scanned 6 known-sensitive endpoint(s), e.g.: /.//.env, //.env, /core/.env, /info.php, /medi ...
show more
Observed scanned 6 known-sensitive endpoint(s), e.g.: /.//.env, //.env, /core/.env, /info.php, /media../.env, /server/.env
show less
Bad Web Bot
Web App Attack