๐บ๐ธ
1gz
2026-10-01 05:56:23
(14 hours ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /script.js
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ณ
dineshskt4all
2026-10-01 05:24:16
(15 hours ago)
34.95.11.64 - - [01/Oct/2026:05:24:13 +0000] "GET /5v3pojzjdjl3s2nttcli HTTP/1.1" 404 3515 "-" "Mozi ...
show more
34.95.11.64 - - [01/Oct/2026:05:24:13 +0000] "GET /5v3pojzjdjl3s2nttcli HTTP/1.1" 404 3515 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
IoT Targeted
๐ฉ๐ช
ger-stg-sifi1
2026-10-01 05:09:34
(15 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
H24
2026-10-01 04:49:54
(15 hours ago)
//.env /wp-config.old /static//home/user/.env /@fs/app/.env /dist../.env /@fs/home/ubuntu/.aws/crede ...
show more
//.env /wp-config.old /static//home/user/.env /@fs/app/.env /dist../.env /@fs/home/ubuntu/.aws/credentials /.//.env /@fs/.env /@fs/home/ec2-user/.aws/credentials /build../.env
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-01 03:19:16
(17 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐น๐ท
eryilmaz
2026-10-01 02:07:00
(18 hours ago)
Automated attack blocked by eryilmaz WAF/defense engine (level 1, source: auto, path: /signin)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 01:44:00
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.11.64 (64.11.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.11.64 (64.11.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:43:52.800769 2026] [security2:error] [pid 2537:tid 2537] [client 34.95.11.64:55330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bonefrog.com"] [uri "/.htpasswd"] [unique_id "ar262J5IqLd_ko8sqVO9XwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-01 00:51:00
(19 hours ago)
207 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
Anonymous
2026-10-01 00:30:02
(19 hours ago)
CrowdSec decision: crowdsecurity/http-crawl-non_statics (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-01 00:24:31
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.95.11.64 (64.11.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.11.64 (64.11.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:24:27.483195 2026] [security2:error] [pid 16581:tid 16581] [client 34.95.11.64:37024] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||psychologists-omega.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "psychologists-omega.com"] [uri "/z9x8c7v6b5-debug-trigger-psychologists-omega.com"] [unique_id "ar2oO7bAa3bQMEU8LtzrMAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-30 23:21:08
(21 hours ago)
34.95.11.64 - - [30/Sep/2026:19:21:08 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 5798 "-" "Mozilla/5.0 ( ...
show more
34.95.11.64 - - [30/Sep/2026:19:21:08 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 5798 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.95.11.64 - - [30/Sep/2026:19:21:08 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 5798 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
34.95.11.64 - - [30/Sep/2026:19:21:08 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 5798 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 22:43:09
(21 hours ago)
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.95.11.64 - - [01/Oct/2026:00:42:50 +0200] "GET /.ssh/config HTTP/2.0" 404 109390 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 22:40:03
(21 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
todix
2026-09-30 18:00:38
(1 day ago)
WebAttack or semilar from 34.95.11.64
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:47:50
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.95.11.64 (64.11.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.95.11.64 (64.11.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:47:45.882185 2026] [security2:error] [pid 1334:tid 1334] [client 34.95.11.64:48850] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.caribbeancoders.com|F|2"] [data ".caribbeancoders.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.caribbeancoders.com"] [uri "/z9x8c7v6b5-debug-trigger-www.caribbeancoders.com"] [unique_id "ar0hEd9y92T-cFlBdbw91gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack