Anonymous
2026-09-09 18:16:12
(2 hours ago)
Bot / seems abusive / Apache connections: 38
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇳🇱
svr
2026-09-09 16:25:56
(4 hours ago)
Abusive Automated Web Scanner
Web App Attack
🇫🇷
IRISIO
2026-09-09 15:57:17
(4 hours ago)
scans/SQL injection/spam posts : 1808 queries
Web App Attack
SQL Injection
🇺🇸
TPI-Abuse
2026-09-09 14:00:07
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.223.28 (28.223.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.223.28 (28.223.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:59:55.842750 2026] [security2:error] [pid 27561:tid 27561] [client 35.204.223.28:57692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lunchtimers.org"] [uri "/@fs/.env"] [unique_id "aqFmW2jFkIGNaSP9AZXCWQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:34:36
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.223.28 (28.223.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.223.28 (28.223.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:34:28.134344 2026] [security2:error] [pid 25421:tid 25421] [client 35.204.223.28:64150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.salazartransfers.com"] [uri "/@fs/../../.env"] [unique_id "aqFgZCZwqqE91oz6ZxthtAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-09 12:30:30
(8 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 11:25:00
(9 hours ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
oja
2026-09-09 10:45:00
(9 hours ago)
Aggressive web scanner
Web App Attack
🇫🇷
masterguru
2026-09-09 10:12:46
(10 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-09 10:05:47
(10 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:51:13
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.223.28 (28.223.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.223.28 (28.223.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:51:07.764380 2026] [security2:error] [pid 12691:tid 12691] [client 35.204.223.28:32656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.teghekatu24.am"] [uri "/@fs/root/.env"] [unique_id "aqEd-1BBnZdr-7RnEcrrzgAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 08:32:48
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.223.28 (28.223.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.223.28 (28.223.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:32:40.357901 2026] [security2:error] [pid 28739:tid 28753] [client 35.204.223.28:41778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wasula.com"] [uri "/@fs/root/.env"] [unique_id "aqEZqDjIDGkNGWwQTlgSRgAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
alessio loto
2026-09-09 08:17:57
(12 hours ago)
WAF Detection: SQLi_in_Referer (High Risk IP). AI Confirmed Attack Payload.
Web App Attack
🇳🇱
Savvii
2026-09-09 08:03:53
(12 hours ago)
20 attempts against mh-misbehave-ban on mars
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-09 08:03:46
(12 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /aws/.env.production
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.2286.7 Safari/537.36 Edg/134.0.2286.7; compatible; GPTBot/1.4; +https://openai.com/gptbot
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot