๐ซ๐ฎ
as211431.net
2026-09-30 04:51:46
(19 hours ago)
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: BLOCK
Protocol: HTTP/2 (POST method ...
show more
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /index.php
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
e.fierstra
2026-09-30 04:32:45
(20 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-30 04:13:44
(20 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ธ๐ฌ
mypatricks
2026-09-30 02:10:04
(22 hours ago)
35.199.104.145 | Port: 11654 | DNS: 145.104.199.35.bc.googleusercontent.com 2026-09-30T10:10:02+08:0 ...
show more
35.199.104.145 | Port: 11654 | DNS: 145.104.199.35.bc.googleusercontent.com 2026-09-30T10:10:02+08:00 America/Sao_Paulo | Fake GoogleBot Detected | UA: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) HTTP/1.1 443 GET | URL: /api/settings | Ref: - | Country: BR/Brazil/โ05:00 IP City: Sรฃo Paulo a42fb05fac1a2395-GRU/Sรฃo Paulo, Brazil 5 hits/3 secs Robots 0
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐ฌ๐ง
andypiper
2026-09-30 01:00:39
(23 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-30 00:29:22
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
pearbright
2026-09-30 00:25:23
(1 day ago)
[Wed Sep 30 00:25:22.511043 2026] [php:error] [pid 1978557:tid 1978557] [client 35.199.104.145:60554 ...
show more
[Wed Sep 30 00:25:22.511043 2026] [php:error] [pid 1978557:tid 1978557] [client 35.199.104.145:60554] script '/var/www/deary/html/i.php' not found or unable to stat
[Wed Sep 30 00:25:22.924897 2026] [php:error] [pid 1978557:tid 1978557] [client 35.199.104.145:60554] script '/var/www/deary/html/app_dev.php' not found or unable to stat
...
show less
Web App Attack
๐ฉ๐ช
MarkGGN
2026-09-30 00:18:32
(1 day ago)
Web attack. 35.199.104.145 - - [30/Sep/2026:02:18:31 +0200] "GET /auth/login HTTP/2.0" 302 138 "-" " ...
show more
Web attack. 35.199.104.145 - - [30/Sep/2026:02:18:31 +0200] "GET /auth/login HTTP/2.0" 302 138 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
35.199.104.145 - - [30/Sep/2026:02:18:31 +0200] "GET /admin/login HTTP/2.0" 302 138 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:15:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.104.145 (145.104.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.104.145 (145.104.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:15:50.793425 2026] [security2:error] [pid 25599:tid 25599] [client 35.199.104.145:45768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deerchristmascards.com"] [uri "/src/.env"] [unique_id "arxUtrn5fRMWSgNHlMouEAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-29 23:27:18
(1 day ago)
3.740 requests from abuseipdb.com blacklisted IP (1yr6mos3w)
Brute-Force
Bad Web Bot
๐ง๐ท
radardatelecom
2026-09-29 22:26:02
(1 day ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 22:04:48
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 35.199.104.145 (145.104.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.199.104.145 (145.104.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:04:40.208597 2026] [security2:error] [pid 3717:tid 3717] [client 35.199.104.145:55606] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||delstarr.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "delstarr.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "arw1-NH6QtW8dU1uSu3KBQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-29 21:59:28
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-29
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-29 20:58:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.104.145 (145.104.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.104.145 (145.104.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:57:54.788230 2026] [security2:error] [pid 24112:tid 24112] [client 35.199.104.145:33214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dekosh.koshland.us"] [uri "/.env.save"] [unique_id "arwmUsCobzAwLyyrFWKpvgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 20:08:26
(1 day ago)
Portscan: TCP/8443 (12x), TCP/8080 (11x), TCP/443 (2x), TCP/80
Port Scan