🇺🇸
TPI-Abuse
2026-09-07 03:29:51
(5 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.255.205.237 (237.205.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.255.205.237 (237.205.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:29:45.580338 2026] [security2:error] [pid 18870:tid 18870] [client 35.255.205.237:58294] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||www.iotgardening.nextngnr.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.iotgardening.nextngnr.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap4vqXdfy6-DFLJcOfnIwAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 02:05:16
(7 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
Anonymous
2026-09-06 23:55:02
(9 hours ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 23:50:49
(9 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.255.205.237 (237.205.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.255.205.237 (237.205.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:50:45.338346 2026] [security2:error] [pid 18632:tid 18652] [client 35.255.205.237:44512] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||newleafpro.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "newleafpro.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap38VbioqdKhRHDUEw0dxgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-06 22:26:53
(11 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /wp-config.php~
UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 21:28:31
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.205.237 (237.205.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.205.237 (237.205.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:28:27.834452 2026] [security2:error] [pid 31284:tid 31284] [client 35.255.205.237:46872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jamessummers.org"] [uri "/@fs/src/.env"] [unique_id "ap3a-6F27df0N1nGH6az0AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 21:14:51
(12 hours ago)
Excessive multi-domain requests
Brute-Force
🇭🇺
IloGus
2026-09-06 19:45:55
(13 hours ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/env/aws_credenti ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/env/aws_credentials.env via rule: /config
show less
Web App Attack
Brute-Force
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 19:29:05
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.205.237 (237.205.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.205.237 (237.205.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:28:58.977991 2026] [security2:error] [pid 25061:tid 25061] [client 35.255.205.237:42380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.catzpaw.com"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "ap2--l6oZ7eQ0DS8pxR21AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lavnet.net
2026-09-06 19:19:22
(14 hours ago)
35.255.205.237 - - [06/Sep/2026:19:19:21 +0000] "GET /rclone.conf HTTP/2.0" 404 1878 "-" "Mozilla/5. ...
show more
35.255.205.237 - - [06/Sep/2026:19:19:21 +0000] "GET /rclone.conf HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.255.205.237 - - [06/Sep/2026:19:19:21 +0000] "GET /key.pem HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.255.205.237 - - [06/Sep/2026:19:19:21 +0000] "GET /z9x8c7v6b5-debug-trigger-jackaltx.com HTTP/2.0" 404 1855 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.255.205.237 - - [06/Sep/2026:19:19:21 +0000] "GET /id_ecdsa HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.255.205.237 - - [06/Sep/2026:19:19:21 +0000] "GET /id_ed25519 HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
35.255.205.237 - - [06/Sep/2026:19:19:21 +0000] "GET /server.key HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
...
show less
Brute-Force
Anonymous
2026-09-06 18:43:12
(14 hours ago)
suspicious behavior
Blog Spam
Brute-Force
Web App Attack
🇩🇪
bazter.pro
2026-09-06 18:02:46
(15 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 17:30:47
(15 hours ago)
[da.kdns.gr] httpd-config-scan: sites=www.i-pad.gr; logs=/var/log/httpd/domains/i-pad.gr.log; sample ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.i-pad.gr; logs=/var/log/httpd/domains/i-pad.gr.log; samples=/api%2F.env | /settings%2F.env | /@fs/.env?url&raw??
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:24:54
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.255.205.237 (237.205.255.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.255.205.237 (237.205.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:24:46.362311 2026] [security2:error] [pid 6045:tid 6045] [client 35.255.205.237:38388] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rustyog.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rustyog.net"] [uri "/rclone.conf"] [unique_id "ap2h3gg9hk5nWxFSeKYm8QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Mendip_Defender
2026-09-06 17:13:06
(16 hours ago)
35.255.205.237 - - [06/Sep/2026:18:13:18 +0100] "GET /user/login HTTP/1.1" 404 6497 "-" "Mozilla/5.0 ...
show more
35.255.205.237 - - [06/Sep/2026:18:13:18 +0100] "GET /user/login HTTP/1.1" 404 6497 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
35.255.205.237 - - [06/Sep/2026:18:13:18 +0100] "GET /users/login HTTP/1.1" 404 6497 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
35.255.205.237 - - [06/Sep/2026:18:13:18 +0100] "GET /admin HTTP/1.1" 404 6497 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
...
show less
Hacking
Web App Attack