๐บ๐ธ
TPI-Abuse
2026-07-21 01:37:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 13.217.93.86 (ec2-13-217-93-86.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 13.217.93.86 (ec2-13-217-93-86.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 21:37:27.469419 2026] [security2:error] [pid 19319:tid 19319] [client 13.217.93.86:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcbrude.com"] [uri "/.git/config"] [unique_id "al7NVxzW5_CV7-Ejel3QEwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 22:45:02
(3 days ago)
suspicious request in access.log
Web App Attack
๐ต๐ฑ
srebrakowski.com
2026-07-20 18:58:01
(3 days ago)
crowdsec/crowdsecurity/appsec-vpatch
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-20 08:43:42
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 13.217.93.86 (ec2-13-217-93-86.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 13.217.93.86 (ec2-13-217-93-86.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 04:43:38.656234 2026] [security2:error] [pid 12347:tid 12347] [client 13.217.93.86:39238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aandsmetal.com"] [uri "/.git/config"] [unique_id "al3fuuquaqMmPVqo_sjNCwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-07-20 08:29:03
(4 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based)
show less
Hacking
Web App Attack
๐ซ๐ฎ
as211431.net
2026-07-20 08:06:06
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-20 06:36:00
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 13.217.93.86 (ec2-13-217-93-86.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 13.217.93.86 (ec2-13-217-93-86.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 02:35:56.388711 2026] [security2:error] [pid 15633:tid 15633] [client 13.217.93.86:37722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "monmouthbottleshop.com"] [uri "/.git/config"] [unique_id "al3BzDCJPg_Huy-sEOhNtgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-20 06:00:00
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
myintarweb
2026-07-20 02:44:24
(4 days ago)
13.217.93.86 - - [20/Jul/2026:03:44:23 +0100] 443 "GET /.env HTTP/1.1" 404 29969 "-" "Mozilla/5.0 (X ...
show more
13.217.93.86 - - [20/Jul/2026:03:44:23 +0100] 443 "GET /.env HTTP/1.1" 404 29969 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-20 02:42:25
(4 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 01:42:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 13.217.93.86 (ec2-13-217-93-86.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 13.217.93.86 (ec2-13-217-93-86.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 21:42:21.155048 2026] [security2:error] [pid 2500831:tid 2500831] [client 13.217.93.86:47240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coloradohifi.com"] [uri "/.git/config"] [unique_id "al18_SBdf71DOwRGdxc8XgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-07-20 01:24:02
(4 days ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/config ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/config Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
Gwyneth Llewelyn
2026-07-20 01:20:23
(4 days ago)
2026/07/20 02:20:21 [error] 1770200#1770200: *74302 access forbidden by rule, client: 13.217.93.86, ...
show more
2026/07/20 02:20:21 [error] 1770200#1770200: *74302 access forbidden by rule, client: 13.217.93.86, server: bestasquadradas.org, request: "GET /.env HTTP/2.0", host: "bestasquadradas.org"
13.217.93.86 - - [20/Jul/2026:02:20:21 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; WebView/3.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36 Edge/18.17763"
13.217.93.86 - - [20/Jul/2026:02:20:22 +0100] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5) AppleWebKit/618.3.5 (KHTML, like Gecko) Version/17.4 Safari/618.3.5"
show less
Brute-Force
Web App Attack
Anonymous
2026-07-19 23:45:28
(4 days ago)
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-07-19 22:44:11
(4 days ago)
Login credentials theft attempt
Hacking