🇺🇸
TPI-Abuse
2026-09-04 01:08:45
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.130.15 (15.130.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.130.15 (15.130.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:08:37.350524 2026] [security2:error] [pid 3095:tid 3095] [client 104.199.130.15:48258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uosmikvah.passy.us"] [uri "/.git/config"] [unique_id "apoaFR8sCq6OewvbTcP-CwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 00:11:29
(3 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 104.199.130.15 (TW/Taiwan/15.130.199. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 104.199.130.15 (TW/Taiwan/15.130.199.104.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇩🇪
Vegascosmetics
2026-09-03 23:20:07
(3 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-09-03 22:59:46
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-03 22:01:06
(5 hours ago)
Auto-ban: >3000 req/min op 2026-09-03
Web App Attack
SSH
Hacking
Anonymous
2026-09-03 18:15:33
(8 hours ago)
[ssd1.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/app/.git/config | /public ...
show more
[ssd1.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/app/.git/config | /public/.git/config | /.git/config
show less
Hacking
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-03 17:49:46
(9 hours ago)
[03/Sep/2026:20:49:46 +0300] -- 104.199.130.15 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[03/Sep/2026:20:49:46 +0300] -- 104.199.130.15 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 16:19:52
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.130.15 (15.130.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.130.15 (15.130.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:19:45.878280 2026] [security2:error] [pid 1094:tid 1094] [client 104.199.130.15:59966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "friendlyfarmforfun.com"] [uri "/src/.git/config"] [unique_id "apmeIQooUf5eW-k7J5JozAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-03 14:56:07
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-03 14:46:52
(12 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-03 12:49:01
(14 hours ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /htdocs/.git/config
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-03 09:52:03
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.130.15 (15.130.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.130.15 (15.130.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:51:59.834806 2026] [security2:error] [pid 22628:tid 22628] [client 104.199.130.15:48104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.arcdesign.me"] [uri "/site/.git/config"] [unique_id "aplDP8voKUTEOMcwpTDleAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 07:36:37
(19 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-03 06:44:17
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.130.15 (15.130.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.130.15 (15.130.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 02:44:13.734654 2026] [security2:error] [pid 16288:tid 16288] [client 104.199.130.15:58452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "klingandi.com.bridgital.com"] [uri "/.git/config"] [unique_id "apkXPbzI4AF97beaZarEAgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack