π©πͺ
TheDjRider
2026-09-30 00:21:14
(8 minutes ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-30T00:21:12.676407247Z. Context: http_status=404
show less
Web App Attack
πΊπΈ
interbiznw.com
2026-09-30 00:02:34
(27 minutes ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
π«π·
arsonist
2026-09-29 22:52:20
(1 hour ago)
[fail2ban]
2026-09-29T22:52:19.670138+00:00 arson caddy[1890453]: {"level":"info","ts":1790722339.67 ...
show more
[fail2ban]
2026-09-29T22:52:19.670138+00:00 arson caddy[1890453]: {"level":"info","ts":1790722339.6701074,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"104.248.125.109","remote_port":"35660","client_ip":"104.248.125.109","proto":"HTTP/1.1","method":"GET","host":"arson.cloud","uri":"/.git/config","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"],"Accept-Encoding":["gzip, deflate"],"Accept":["*/*"],"Connection":["keep-alive"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"arson.cloud","ech":false}},"bytes_read":0,"user_id":"","duration":0.000083868,"size":7,"status":418,"resp_headers":{"Content-Type":["text/plain; charset=utf-8"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Strict-Transport-Security":["max-age=15552000; incl
...
show less
Bad Web Bot
π¬π§
pinguin
2026-09-29 22:35:39
(1 hour ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π³π±
homeshowdomain.nl
2026-09-29 22:00:50
(2 hours ago)
Auto-ban: >3000 req/min op 2026-09-29
Web App Attack
SSH
Hacking
Anonymous
2026-09-29 21:07:16
(3 hours ago)
"GET /.git/config HTTP/1.1"
Hacking
Web App Attack
π¦πΊ
paulshipley.com.au
2026-09-29 20:47:24
(3 hours ago)
[Wed Sep 30 06:47:23.478571 2026] [security2:error] [pid 278409] [client 104.248.125.109:43142] [cli ...
show more
[Wed Sep 30 06:47:23.478571 2026] [security2:error] [pid 278409] [client 104.248.125.109:43142] [client 104.248.125.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "angleseaarthouse.com.au"] [uri "/.git/config"] [unique_id "arwj2_UbDiDU7dM2yiejDAAAABg"]
...
show less
Web App Attack
π¦πΊ
paulshipley.com.au
2026-09-29 20:19:35
(4 hours ago)
[Wed Sep 30 06:19:34.202034 2026] [security2:error] [pid 273757] [client 104.248.125.109:58372] [cli ...
show more
[Wed Sep 30 06:19:34.202034 2026] [security2:error] [pid 273757] [client 104.248.125.109:58372] [client 104.248.125.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "angleseaarthouse.com.au"] [uri "/.git/config"] [unique_id "arwdVqIBLR6gcoz2bAvpNgAAABA"]
...
show less
Web App Attack
Anonymous
2026-09-29 18:28:20
(6 hours ago)
fail2ban_an apache-modsecurity [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.git/c ...
show more
fail2ban_an apache-modsecurity [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.git/config"]
show less
Bad Web Bot
Web App Attack
π©πͺ
TheDjRider
2026-09-29 17:00:48
(7 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-29T17:00:47.234314939Z. Context: http_status=404
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 15:25:25
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.248.125.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 104.248.125.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 11:25:22.484018 2026] [security2:error] [pid 16960:tid 16960] [client 104.248.125.109:52876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arttechnology.net"] [uri "/.git/config"] [unique_id "arvYYrgoKCeRI51v0GAkDQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Blexyel
2026-09-29 15:14:13
(9 hours ago)
104.248.125.109 - - [29/Sep/2026:17:14:13 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5. ...
show more
104.248.125.109 - - [29/Sep/2026:17:14:13 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 14:54:58
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.248.125.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 104.248.125.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 10:54:54.942996 2026] [security2:error] [pid 12835:tid 12835] [client 104.248.125.109:41920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "appalachianfieldstofamilies.org"] [uri "/.git/config"] [unique_id "arvRPuI5aWp5AQRSGIdlcAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 13:44:11
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.248.125.109 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 104.248.125.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:44:08.950285 2026] [security2:error] [pid 4919:tid 4919] [client 104.248.125.109:56834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "azfilmguild.org"] [uri "/.git/config"] [unique_id "arvAqBOpuWGAw8h5hmwszwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
n2nguyenn2nguyen
2026-09-29 13:31:13
(10 hours ago)
Blocked by YFC Security on https://brixzly.com β type: directory_scan_attempts
Web App Attack