Anonymous
2026-08-26 17:42:17
(6 minutes ago)
104.199.165.58 - - [27/Aug/2026:01:42:17 +0800] "GET /.git/config HTTP/1.1" 200 30687 "-" "Mozilla/5 ...
show more
104.199.165.58 - - [27/Aug/2026:01:42:17 +0800] "GET /.git/config HTTP/1.1" 200 30687 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-08-26 17:38:00
(10 minutes ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-08-26 17:33:47
(14 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
sdos.es
2026-08-26 17:32:29
(16 minutes ago)
"Restricted File Access Attempt - Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-26 17:28:56
(19 minutes ago)
cloudlinux2 fail2ban: 2026-08-26 19:23:49,060 fail2ban.filter [1775]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-26 19:23:49,060 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 136.244.91.143 - 2026-08-26 19:23:48cloudlinux2 fail2ban: 2026-08-26 19:23:59,859 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 35.197.142.114 - 2026-08-26 19:23:59cloudlinux2 fail2ban: 2026-08-26 19:24:05,775 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 41.235.177.212 - 2026-08-26 19:24:05cloudlinux2 fail2ban: 2026-08-26 19:24:16,999 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 41.235.177.212 - 2026-08-26 19:24:16cloudlinux2 fail2ban: 2026-08-26 19:24:17,354 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Ban 41.235.177.212cloudlinux2 fail2ban: 2026-08-26 19:24:17,360 fail2ban.filter [1775]: INFO [recidive] Found 41.235.177.212 - 2026-08-26 19:24:17cloudlinux2 fail2ban: 2026-08-26 19:24:27,754 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 104.199.165.58 - 2026-08-26 19:24:27cloudlinux2 fail2ban: 2
show less
Web App Attack
๐ฉ๐ช
macrob
2026-08-26 17:28:41
(19 minutes ago)
2026/08/26 17:28:38 [error] 2096800#2096800: *523514304 access forbidden by rule, client: 104.199.16 ...
show more
2026/08/26 17:28:38 [error] 2096800#2096800: *523514304 access forbidden by rule, client: 104.199.165.58, server: binixo.pl, request: "GET /.git/config HTTP/2.0", host: "binixo.pl"
2026/08/26 17:28:39 [error] 2096802#2096802: *523597678 access forbidden by rule, client: 104.199.165.58, server: binixo.com.ar, request: "GET /.git/config HTTP/2.0", host: "binixo.com.ar"
2026/08/26 17:28:40 [error] 2096802#2096802: *523597694 access forbidden by rule, client: 104.199.165.58, server: binixo.com, request: "GET /.git/config HTTP/2.0", host: "binixo.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 17:27:20
(21 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.199.165.58 (58.165.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.165.58 (58.165.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:27:15.614893 2026] [security2:error] [pid 16631:tid 16631] [client 104.199.165.58:21372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boaredraven.com"] [uri "/.git/config"] [unique_id "ao8h84sannorsNDHSbU72QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-26 17:23:33
(25 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 17:12:35
(36 minutes ago)
104.199.165.58 - - [26/Aug/2026:17:12:35 +0000] "GET /.git/config HTTP/1.1" 404 4307 "-" "Mozilla/5. ...
show more
104.199.165.58 - - [26/Aug/2026:17:12:35 +0000] "GET /.git/config HTTP/1.1" 404 4307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 17:12:09
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.199.165.58 (58.165.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.165.58 (58.165.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:12:05.477531 2026] [security2:error] [pid 23724:tid 23724] [client 104.199.165.58:26016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "benchmarkbcs.com"] [uri "/.git/config"] [unique_id "ao8eZcSAiSnFlJN8-84MCQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-26 17:04:58
(43 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-08-26 17:00:14
(48 minutes ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-08-26 16:57:48
(50 minutes ago)
git/env leak probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 16:56:12
(52 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.199.165.58 (58.165.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.165.58 (58.165.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:56:04.950317 2026] [security2:error] [pid 5034:tid 5034] [client 104.199.165.58:63092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billhoy.com"] [uri "/.git/config"] [unique_id "ao8apJyEFR5RRUNY4_kqUQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-08-26 16:45:12
(1 hour ago)
Login credentials theft attempt
Hacking