๐บ๐ธ
1gz
2026-10-03 03:34:24
(2 hours ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST me ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST method)
Endpoint: /index.php
UA: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
bazter.pro
2026-10-03 03:20:53
(2 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
JLKnoch Software GmbH
2026-10-03 03:13:12
(2 hours ago)
CrowdSec crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 00:57:07
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.213.70 (70.213.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.213.70 (70.213.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 20:57:00.964915 2026] [security2:error] [pid 13803:tid 13803] [client 35.201.213.70:59554] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||adurpartners.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adurpartners.com"] [uri "/z9x8c7v6b5-debug-trigger-adurpartners.com"] [unique_id "asBS3OCvxzJ70Gmmlu4eyAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-10-03 00:08:10
(5 hours ago)
Malformed or malicious web request
35.201.213.70 - - [03/Oct/2026:02:08:08 +0200] "POST /lib/termina ...
show more
Malformed or malicious web request
35.201.213.70 - - [03/Oct/2026:02:08:08 +0200] "POST /lib/terminal-xhr.php HTTP/2.0" 404 4174 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
show less
Hacking
Web App Attack
๐บ๐ธ
factor1
2026-10-02 21:11:58
(8 hours ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐ซ๐ท
Octopuce
2026-10-02 20:37:24
(9 hours ago)
Aggressive web search of vulnerable pages: /api/v1/config/ /__debug__/ /api/console/api_server?sense ...
show more
Aggressive web search of vulnerable pages: /api/v1/config/ /__debug__/ /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../ ...
show less
Web App Attack
๐ซ๐ฎ
albionfreemarket.com
2026-10-02 20:30:36
(9 hours ago)
35.201.213.70 - - [02/Oct/2026:20:30:33 +0000] "POST /graphql HTTP/2.0" 403 555 "https://albionfreem ...
show more
35.201.213.70 - - [02/Oct/2026:20:30:33 +0000] "POST /graphql HTTP/2.0" 403 555 "https://albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "TW"
35.201.213.70 - - [02/Oct/2026:20:30:34 +0000] "POST /api/graphql HTTP/2.0" 403 555 "https://albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "TW"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
MakoWish
2026-10-02 20:29:39
(9 hours ago)
Fuzzing for misconfigured web servers.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:11:46
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.213.70 (70.213.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.213.70 (70.213.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:11:41.611392 2026] [security2:error] [pid 30802:tid 30802] [client 35.201.213.70:59308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.austintrauma.com"] [uri "/static../.env"] [unique_id "ar_XvUizxF2X3nMspiPt0AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-02 15:11:18
(14 hours ago)
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. ...
show more
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. Automatic ban triggered. Detection time (UTC): 2026-10-02T15:11:13.510289888Z. Context: http_status=301, http_status=404
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:42:59
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.213.70 (70.213.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.213.70 (70.213.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:42:56.046951 2026] [security2:error] [pid 22239:tid 22239] [client 35.201.213.70:45706] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.acmax.com|F|2"] [data ".acmax.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.acmax.com"] [uri "/z9x8c7v6b5-debug-trigger-www.acmax.com"] [unique_id "ar_C8Gw2LP8Hc6Rb8hQyugAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:46:29
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.213.70 (70.213.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.213.70 (70.213.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:46:24.729984 2026] [security2:error] [pid 6513:tid 6513] [client 35.201.213.70:55578] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amtnm.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amtnm.com"] [uri "/z9x8c7v6b5-debug-trigger-amtnm.com"] [unique_id "ar-1sFijFhKu5G5o7QF3tAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:22:01
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.213.70 (70.213.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.213.70 (70.213.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:21:56.127893 2026] [security2:error] [pid 17398:tid 17398] [client 35.201.213.70:55872] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.abbeygardensllandudno.com|F|2"] [data ".abbeygardensllandudno.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.abbeygardensllandudno.com"] [uri "/z9x8c7v6b5-debug-trigger-www.abbeygardensllandudno.com"] [unique_id "ar-v9FOsJhCYgkpsw_8-2AAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 12:07:04
(17 hours ago)
Automated web scanner. Requested suspicious paths: /forgot-password | /z9x8c7v6b5-debug-trigger-api. ...
show more
Automated web scanner. Requested suspicious paths: /forgot-password | /z9x8c7v6b5-debug-trigger-api.tigzig.com | /reset-password | /login. UTC: 2026-10-02 11:51:38.
show less
Web App Attack