๐บ๐ธ
TPI-Abuse
2026-09-21 06:11:15
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:11:12.553563 2026] [security2:error] [pid 19967:tid 19967] [client 35.236.136.63:33454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.breinesberger.com"] [uri "/.env.js"] [unique_id "arDKgMFRbJ3M45offyEuzAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 06:08:21
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 05:42:40
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:42:35.889410 2026] [security2:error] [pid 23234:tid 23234] [client 35.236.136.63:55966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jannetta.com"] [uri "/@fs/app/.env"] [unique_id "arDDy26GoP-lAyC7LCP1GgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:17:19
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.136.63 (63.136.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.136.63 (63.136.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:17:11.236942 2026] [security2:error] [pid 29222:tid 29222] [client 35.236.136.63:47428] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bundrenfarmstn.com|F|2"] [data ".bundrenfarmstn.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bundrenfarmstn.com"] [uri "/z9x8c7v6b5-debug-trigger-www.bundrenfarmstn.com"] [unique_id "arC9110rEnF635eL_TiQsgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-21 05:14:05
(10 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-21 05:12:53
(10 hours ago)
Triggered Cloudflare WAF (firewallManaged) from TW.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from TW.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 04:44:20
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:44:12.742722 2026] [security2:error] [pid 17466:tid 17492] [client 35.236.136.63:55632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "btoelsalvador.com"] [uri "/.env"] [unique_id "arC2HATCiVTmeAKrH82ePQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 04:37:00
(11 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.236.136.63 (TW/Taiwan/63.136.236.3 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.236.136.63 (TW/Taiwan/63.136.236.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 04:15:40
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.136.63 (63.136.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.136.63 (63.136.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:15:35.626430 2026] [security2:error] [pid 3187:tid 3196] [client 35.236.136.63:44144] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.buy-optimum.com|F|2"] [data ".buy-optimum.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.buy-optimum.com"] [uri "/z9x8c7v6b5-debug-trigger-www.buy-optimum.com"] [unique_id "arCvZ0tJrWe6JJdwU9vtAAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:52:28
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:52:23.930267 2026] [security2:error] [pid 28178:tid 28178] [client 35.236.136.63:57630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bosozuki.com"] [uri "/.git/config"] [unique_id "arCp9zDGyX5r-dvLgiW1rQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:26:59
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:26:55.609979 2026] [security2:error] [pid 9222:tid 9222] [client 35.236.136.63:60340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fatcavestudios.com"] [uri "/.github/.env"] [unique_id "arCj_yN4DO7UdrRiRebxKwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-09-21 03:11:02
(12 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:09:46
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.136.63 (63.136.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:09:42.755900 2026] [security2:error] [pid 15640:tid 15640] [client 35.236.136.63:44158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.braleygroup.com"] [uri "/.git/config"] [unique_id "arB1xk6t4WM5MjMif_j0agAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 23:38:51
(16 hours ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.236.136.63 - - [21/Sep/2026:01:38:51 +0200] "GET /.aws/config HTTP/1.1" 301 5697 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 23:30:25
(16 hours ago)
Multiple WAF Violations
Web App Attack