๐จ๐ฆ
1gz
2026-06-03 13:40:44
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /stats.json
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
LRob
2026-06-03 13:00:07
(2 months ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ณ๐ฑ
vaddilyin
2026-06-03 12:28:32
(2 months ago)
{"ClientAddr":"85.121.54.238:34440","ClientHost":"85.121.54.238","ClientPort":"34440","ClientUsernam ...
show more
{"ClientAddr":"85.121.54.238:34440","ClientHost":"85.121.54.238","ClientPort":"34440","ClientUsername":"-","DownstreamContentSize":19,"DownstreamStatus":404,"Duration":39765,"GzipRatio":0,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":39765,"RequestAddr":"post.vdkln.com","RequestContentSize":0,"RequestCount":44040,"RequestHost":"post.vdkln.com","RequestMethod":"GET","RequestPath":"/.git/config","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"StartLocal":"2026-06-03T12:28:25.146267316Z","StartUTC":"2026-06-03T12:28:25.146267316Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"websecure","level":"info","msg":"","time":"2026-06-03T12:28:25Z"}
{"ClientAddr":"85.121.54.238:34440","ClientHost":"85.121.54.238","ClientPort":"34440","ClientUsername":"-","DownstreamContentSize":19,"DownstreamStatus":404,"Duration":34289,"GzipRatio":0,"OriginContentSize":0,"OriginDuration":0,"OriginStatus":0,"Overhead":3428
...
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-06-03 08:19:30
(2 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-03 08:09:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 85.121.54.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.54.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 04:08:56.348493 2026] [security2:error] [pid 13695:tid 13695] [client 85.121.54.238:44796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proboundary.com"] [uri "/.git/config"] [unique_id "ah_hGDr-OsKssmbWTVfkmQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-03 07:59:11
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 05:52:06
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 85.121.54.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 85.121.54.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 01:51:59.219902 2026] [security2:error] [pid 19875:tid 19875] [client 85.121.54.238:34804] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ryanc.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ryanc.net"] [uri "/storage/logs/laravel.log"] [unique_id "ah_A_9o7VBzcBex5koFZcAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 04:38:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 85.121.54.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.54.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 00:38:55.993911 2026] [security2:error] [pid 4625:tid 4625] [client 85.121.54.238:34526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathewyoung.com"] [uri "/.git/config"] [unique_id "ah-v341uqCZLas5l3yIy1gAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 02:46:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 85.121.54.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.54.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 22:46:50.416666 2026] [security2:error] [pid 24946:tid 24946] [client 85.121.54.238:42822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "julianunplugged.com"] [uri "/.git/config"] [unique_id "ah-Vmv9CZ928ItDWBI--XgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-06-03 01:58:57
(2 months ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 85.121.54.238 (-): 2 in the last 3600 se ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 85.121.54.238 (-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 85.121.54.238 - - [03/Jun/2026:03:58:48 +0200] "GET /vault.env HTTP/2.0" 404 71322 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)" "-" host=miafitlab.it
85.121.54.238 - - [03/Jun/2026:03:58:50 +0200] "GET /secrets.yml HTTP/2.0" 404 71344 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-" host=miafitlab.it
show less
Port Scan
๐ซ๐ท
โจ
2026-06-03 01:34:15
(2 months ago)
Domain : threebridges.health
Rule : hack
2026-06-03 01:25:11 ***hidden-privacy*** GET /_next/build-m ...
show more
Domain : threebridges.health
Rule : hack
2026-06-03 01:25:11 ***hidden-privacy*** GET /_next/build-manifest.json - 443 - 85.121.54.238 HTTP/2 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.5304.141 Safari/537.36 MicroMessenger/3.9.10.27135 NetType/WIFI WindowsWechat - threebridges.health 404 0 2 12859 544 51 - -
show less
Hacking
SQL Injection
Brute-Force
๐ซ๐ท
masterguru
2026-06-03 01:14:19
(2 months ago)
Restricted File Access Attempt. Matched phrase "secrets.json" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-06-03 01:05:16
(2 months ago)
Abuse Detected (3)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 00:56:52
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 85.121.54.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.54.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 20:56:46.549052 2026] [security2:error] [pid 22794:tid 22794] [client 85.121.54.238:54802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taltonfamily.com"] [uri "/.git/config"] [unique_id "ah97zl8ofCPmZe_q4KCLJgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
prime_fusion_ld
2026-06-03 00:22:07
(2 months ago)
Blocked by CSF/LFD on vps.primefusion.co.uk. Trigger: 1 Ports: *
Port Scan