🇩🇪
Phenix Info
2026-09-11 05:02:06
(1 hour ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
🇺🇸
Blue Pumpkin
2026-09-11 04:52:06
(1 hour ago)
35.237.83.240 - - [11/Sep/2026:04:52:05 +0000] "GET /_astro/pages/index.astro.mjs.map HTTP/1.1" 302 ...
show more
35.237.83.240 - - [11/Sep/2026:04:52:05 +0000] "GET /_astro/pages/index.astro.mjs.map HTTP/1.1" 302 627 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
🇳🇱
Savvii
2026-09-11 04:51:48
(1 hour ago)
20 attempts against mh-misbehave-ban on plum
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-11 04:50:14
(1 hour ago)
Web App Attack
🇩🇪
XICTRON
2026-09-11 04:10:10
(2 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇩🇪
bazter.pro
2026-09-11 03:49:37
(2 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 03:44:52
(2 hours ago)
Automatically blocked after 7 security events. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 7 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Bad Web Bot
Web App Attack
🇫🇷
mrcrassi
2026-09-11 03:41:15
(2 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /@fs/..%252f..%252f..%252f..%252f..%252froot/.env
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-11 03:35:08
(2 hours ago)
Aggressive web scan
Web App Attack
🇪🇸
robotstxt
2026-09-11 03:32:10
(2 hours ago)
35.237.83.240 - - [11/Sep/2026:03:31:24 +0000] "GET /.aws/credentials HTTP/2.0" 403 48793 "-" "Mozil ...
show more
35.237.83.240 - - [11/Sep/2026:03:31:24 +0000] "GET /.aws/credentials HTTP/2.0" 403 48793 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-" edge="35.237.83.240"
35.237.83.240 - - [11/Sep/2026:03:31:24 +0000] "GET /.git/HEAD HTTP/2.0" 403 48798 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="35.237.83.240"
35.237.83.240 - - [11/Sep/2026:03:31:24 +0000] "GET /z9x8c7v6b5-debug-trigger-fundaciopacopuerto.cat HTTP/2.0" 403 48794 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" "-" edge="35.237.83.240"
35.237.83.240 - - [11/Sep/2026:03:31:24 +0000] "GET /.git/config HTTP/2.0" 403 48793 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-" edge="35.237.83.240"
35.237.83.240 - - [11/Sep/2026:03:31:24 +0000] "GET /.aws/config HTTP/2.0" 403 48772 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-" edge="35.237.83.240"
...
show less
Web App Attack
🇬🇷
setupgr
2026-09-11 03:29:08
(2 hours ago)
(mod_security) mod_security (id:11000011) triggered by 35.237.83.240 (US/United States/South Carolin ...
show more
(mod_security) mod_security (id:11000011) triggered by 35.237.83.240 (US/United States/South Carolina/North Charleston/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:29:05.183841 2026] [security2:error] [pid 556312:tid 556375] [remote 35.237.83.240:52246] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 240.83.237.35.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "ftiaxtomonosou.gr"] [uri "/"] [unique_id "aqN1gflLAiR8boiG5GORRwADwBA"]
show less
Port Scan
🇧🇪
cmbplf
2026-09-11 03:25:40
(2 hours ago)
702 requests with url.path */@fs/*
281 requests with url.path */proc/*
Brute-Force
Bad Web Bot
🇧🇾
lns.bz
2026-09-11 02:49:03
(3 hours ago)
Too many 404 requests [BY]
Web App Attack
🇩🇪
macrob
2026-09-11 02:45:46
(3 hours ago)
2026/09/11 02:45:44 [error] 100826#100826: *998139 access forbidden by rule, client: 35.237.83.240, ...
show more
2026/09/11 02:45:44 [error] 100826#100826: *998139 access forbidden by rule, client: 35.237.83.240, server: fastcredit.net.ua, request: "GET /.profile HTTP/2.0", host: "fastcredit.net.ua"
2026/09/11 02:45:44 [error] 100826#100826: *998139 access forbidden by rule, client: 35.237.83.240, server: fastcredit.net.ua, request: "GET /@fs/src/.env?raw?? HTTP/2.0", host: "fastcredit.net.ua"
2026/09/11 02:45:44 [error] 100827#100827: *997557 access forbidden by rule, client: 35.237.83.240, server: fastcredit.net.ua, request: "GET /@fs/app/.env?raw?? HTTP/2.0", host: "fastcredit.net.ua"
...
show less
Web App Attack
Anonymous
2026-09-11 02:35:04
(3 hours ago)
suspicious request in access.log
Web App Attack