๐บ๐ธ
TPI-Abuse
2026-09-01 21:37:32
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 17:37:24.512781 2026] [security2:error] [pid 18706:tid 18706] [client 136.114.198.146:39624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noramsg.com"] [uri "/www/.git/config"] [unique_id "apdFlBBXeAcLyC3FlzYaUwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
www.winos.me
2026-09-01 21:06:52
(1 hour ago)
Shield: Layer4 Port 9 Trap
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 18:22:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:21:52.478911 2026] [security2:error] [pid 27082:tid 27139] [client 136.114.198.146:42018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.iguanablue.com"] [uri "/backend/.git/config"] [unique_id "apcXwHFm4X0wR39-oHlEPQAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-09-01 16:05:52
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.114.198.146 (US/United States/146.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.114.198.146 (US/United States/146.198.114.136.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 15:00:23
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 11:00:15.339862 2026] [security2:error] [pid 5905:tid 5905] [client 136.114.198.146:48528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "turtletaekwondo.com"] [uri "/htdocs/.git/config"] [unique_id "apbof6zPTS4PxGY0-fbf7AAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:57:46
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:57:38.368566 2026] [security2:error] [pid 30825:tid 30825] [client 136.114.198.146:43284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "railfairofseo.com.powerlinemultimedia.net"] [uri "/www/.git/config"] [unique_id "apavoqOKaBcc6Ct4X8WutgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 10:37:24
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
updown.io
2026-09-01 09:19:50
(13 hours ago)
{"level":"info","ts":1788254390.4281132,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1788254390.4281132,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.114.198.146","remote_port":"48350","client_ip":"136.114.198.146","proto":"HTTP/1.1","method":"GET","host":"status.politcast-uri.ch","uri":"/api/actuator/heapdump","headers":{"Accept":["*/*"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"status.politcast-uri.ch","ech":false}},"bytes_read":0,"user_id":"","duration":0.000085453,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1788254390.4283664,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.114.198.146","remote_port":"48358","client_ip":"136.114.198.146","proto":"HTTP/1.1","method":"GET","host":"status.politcast-uri.ch","uri":"/Admin/p
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:06:55
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:06:50.265333 2026] [security2:error] [pid 28206:tid 28206] [client 136.114.198.146:38158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fivecentmiracle.com"] [uri "/src/.git/config"] [unique_id "apaVqnYzWsUjhu1MQ7b5CgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-09-01 08:20:46
(14 hours ago)
Blocked by ConnMonitor
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:06:47
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:06:41.226735 2026] [security2:error] [pid 13047:tid 13047] [client 136.114.198.146:59750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "area1.idahouspsa.com"] [uri "/backend/.git/config"] [unique_id "apZ5gX73FTsajGvCxraVRAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:44:56
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.114.198.146 (146.198.114.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:44:51.975964 2026] [security2:error] [pid 10651:tid 10651] [client 136.114.198.146:44566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canadianprimarysources.org"] [uri "/api/.git/config"] [unique_id "apZKM1FlxwAYcO0jJ8CIygAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-09-01 02:20:47
(20 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /var/www/.git/config
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
mnsf
2026-09-01 01:05:11
(21 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-08-29 22:45:34
(2 days ago)
Multiple WAF Violations
Web App Attack