๐ง๐ท
Peregrine
2026-09-19 03:09:29
(11 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 144.172.107.161 172.68.3.185 - - [17/Sep/2026:10:04:42 -0 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 144.172.107.161 172.68.3.185 - - [17/Sep/2026:10:04:42 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
show less
Bad Web Bot
๐ฌ๐ง
AvonleaConsulting
2026-09-17 22:58:32
(1 day ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-17 18:04:02
(1 day ago)
[Fri Sep 18 04:04:01.430704 2026] [security2:error] [pid 531524] [client 144.172.107.161:58876] [cli ...
show more
[Fri Sep 18 04:04:01.430704 2026] [security2:error] [pid 531524] [client 144.172.107.161:58876] [client 144.172.107.161] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.git/HEAD"] [unique_id "aqwrkc4R2HOvaccEbszv9AAAAAg"]
...
show less
Web App Attack
๐ซ๐ท
Baking333
2026-09-17 17:44:23
(1 day ago)
[redacted] 144.172.107.161 - - [17/Sep/2026:18:44:22 +0100] "GET /.git/HEAD HTTP/1.1" 302 6758 0/667 ...
show more
[redacted] 144.172.107.161 - - [17/Sep/2026:18:44:22 +0100] "GET /.git/HEAD HTTP/1.1" 302 6758 0/66790 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 443 [redacted] 144.172.107.161 - - [17/Sep/2026:18:44:22 +0100] "GET / HTTP/1.1" 200 8104 0/118304 "https://[redacted]/.git/HEAD" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 443
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 17:38:24
(1 day ago)
144.172.107.161 arduino.ua [17/Sep/2026:20:38:24 +0300] "GET /.git/HEAD HTTP/1.1" 403 548 "-" "Mozil ...
show more
144.172.107.161 arduino.ua [17/Sep/2026:20:38:24 +0300] "GET /.git/HEAD HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 0.000 2808
...
show less
Hacking
SQL Injection
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-17 17:34:46
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/HEAD
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฏ๐ต
Watch40x
2026-09-17 17:14:09
(1 day ago)
Automated report from Watch40x security system. Web application probing detected.
Web App Attack
Anonymous
2026-09-17 16:39:11
(1 day ago)
144.172.107.161 - - [18/Sep/2026:00:39:11 +0800] "GET /.git/HEAD HTTP/1.1" 404 196 "-" "Mozilla/5.0 ...
show more
144.172.107.161 - - [18/Sep/2026:00:39:11 +0800] "GET /.git/HEAD HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 16:28:26
(1 day ago)
"GET /.git/HEAD HTTP/1.1"
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-17 16:02:34
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 14:22:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6ba1::90ac:6ba1 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6ba1::90ac:6ba1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 10:22:13.941694 2026] [security2:error] [pid 27425:tid 27425] [client 2002:90ac:6ba1::90ac:6ba1:55275] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsndetx.com"] [uri "/.git/HEAD"] [unique_id "aqv3lfqamvrleX05qf_9AwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-09-17 14:07:55
(2 days ago)
144.172.107.161 - - [17/Sep/2026:16:07:51 +0200] "GET /.git/HEAD HTTP/1.1" 403 5269 "-" "Mozilla/5.0 ...
show more
144.172.107.161 - - [17/Sep/2026:16:07:51 +0200] "GET /.git/HEAD HTTP/1.1" 403 5269 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-09-17 13:04:47
(2 days ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 144.172.107.161 172.68.3.185 - - [17/Sep/2026:10:04:42 -0 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 144.172.107.161 172.68.3.185 - - [17/Sep/2026:10:04:42 -0300] "GET /.git/HEAD HTTP/1.1" 404 414
show less
Bad Web Bot
๐จ๐ฆ
internetworld
2026-09-17 11:57:59
(2 days ago)
internetworld-prod-01 Fail2Ban ban. Jail=nginx-web-probe-iw. Sanitized automatic report from interne ...
show more
internetworld-prod-01 Fail2Ban ban. Jail=nginx-web-probe-iw. Sanitized automatic report from internetworld.ca server security monitoring.
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 11:31:13
(2 days ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 144.172.107.161 - - [17/Sep/2026:13:31:10 +0200] "GET /.git/HEAD HTTP/2.0" 404 35632 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack