๐ง๐ช
cmbplf
2026-09-30 05:38:53
(3 days ago)
221 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ฉ๐ช
yvoictra
2026-09-30 04:51:57
(3 days ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-probing
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-30 03:24:53
(3 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /wp-config.php~
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-30 03:20:05
(3 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-30 01:27:02
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.200.109 (109.200.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.200.109 (109.200.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:26:58.800449 2026] [security2:error] [pid 5816:tid 5816] [client 34.74.200.109:34376] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nvafc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nvafc.com"] [uri "/z9x8c7v6b5-debug-trigger-nvafc.com"] [unique_id "arxlYuxOZ68J193xfczs-QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:17:04
(4 days ago)
(mod_security) mod_security (id:210580) triggered by 34.74.200.109 (109.200.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.74.200.109 (109.200.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:16:56.464337 2026] [security2:error] [pid 6048:tid 6048] [client 34.74.200.109:59066] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||obfetal.com.utilis.net|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "obfetal.com.utilis.net"] [uri "/userfiles"] [unique_id "arxU-P_q_3f2gwNR9NhVLAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-30 00:02:59
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
Aetherweb Ark
2026-09-29 23:50:23
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 34.74.200.109 (US/United States/109.200.74.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.74.200.109 (US/United States/109.200.74.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 23:10:07
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.200.109 (109.200.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.200.109 (109.200.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:09:59.417677 2026] [security2:error] [pid 32298:tid 32298] [client 34.74.200.109:41996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nwarchitect.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nwarchitect.com"] [uri "/z9x8c7v6b5-debug-trigger-nwarchitect.com"] [unique_id "arxFR4rQVLmazxTAX9_3SgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
pashait
2026-09-29 22:08:16
(4 days ago)
Auto-blocked by Seczar SecureOps โ IPS Web Attack Signature (2 events in 5min) at 2026-09-29 22:08
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-29 21:33:49
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.200.109 (109.200.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.200.109 (109.200.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:33:45.264117 2026] [security2:error] [pid 356:tid 356] [client 34.74.200.109:41254] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||obracad.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "obracad.com"] [uri "/z9x8c7v6b5-debug-trigger-obracad.com"] [unique_id "arwuuU3bTBcoJRpWixt10QAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-29 20:52:53
(4 days ago)
Common web attack from 34.74.200.109.
Web App Attack
๐บ๐ธ
dot.mg
2026-09-29 20:06:04
(4 days ago)
Scan of vulnerable files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:00:31
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 34.74.200.109 (109.200.74.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.74.200.109 (109.200.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:00:27.395776 2026] [security2:error] [pid 5118:tid 5118] [client 34.74.200.109:39144] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||doublenaughtspycar.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "doublenaughtspycar.com"] [uri "/z9x8c7v6b5-debug-trigger-doublenaughtspycar.com"] [unique_id "arwY28ukSLkS4-AVuFZduwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 19:37:05
(4 days ago)
Multiple pen test attempts.
Web App Attack