🇩🇪
Nixwig
2026-09-13 23:14:37
(1 day ago)
149.102.240.78 - - [13/Sep/2026:23:14:36 +0000] "GET /.env HTTP/2.0" 404 736 "-" "Mozilla/5.0 (Windo ...
show more
149.102.240.78 - - [13/Sep/2026:23:14:36 +0000] "GET /.env HTTP/2.0" 404 736 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.64 Safari/537.36 Edg/101.0.1210.47"
149.102.240.78 - - [13/Sep/2026:23:14:36 +0000] "GET /api/.env HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.64 Safari/537.36 Edg/101.0.1210.47"
149.102.240.78 - - [13/Sep/2026:23:14:36 +0000] "GET /.env.production HTTP/2.0" 404 736 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.64 Safari/537.36 Edg/101.0.1210.47"
...
show less
Web App Attack
🇸🇪
EmK530
2026-09-13 19:45:24
(1 day ago)
URL flagged by RegEx: /.git/HEAD
Web App Attack
🇮🇪
AutosOnShow
2026-09-13 16:53:04
(1 day ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-09-13 16:52:28.815 |
Web App Attack
🇬🇧
Smish
2026-07-30 16:52:52
(1 month ago)
HONEYPOT HIT --> Fail2ban time=1785430370 log=2026-07-30T17:52:50+01:00 ip=149.102.240.78 host=as210 ...
show more
HONEYPOT HIT --> Fail2ban time=1785430370 log=2026-07-30T17:52:50+01:00 ip=149.102.240.78 host=as210667.net method=GET uri="/.git/index" status=404 ua="moving-to-bins/1.0" ref="-" rid=7aaa8b4ce745b913737b1488f3191388
show less
Web App Attack
🇺🇸
Major Hostility
2026-07-30 16:35:56
(1 month ago)
"GET /.git/index HTTP/1.1" 404
"GET /.git/index HTTP/1.1" 404
Web App Attack
🇺🇸
TPI-Abuse
2026-07-30 16:31:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 12:31:12.264715 2026] [security2:error] [pid 1615682:tid 1615716] [client 149.102.240.78:34088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arrowsinthequiver.com"] [uri "/.git/index"] [unique_id "amt8UH8nYYxFh8WcUVLiYQAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-30 16:09:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 12:09:33.983551 2026] [security2:error] [pid 2602170:tid 2602170] [client 149.102.240.78:36224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "architech.com"] [uri "/.git/index"] [unique_id "amt3PfITTjXB_Eatxc0CeQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 16:00:03
(1 month ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-07-30 15:45:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 11:45:27.289284 2026] [security2:error] [pid 1509145:tid 1509148] [client 149.102.240.78:37930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aplinet.com"] [uri "/.git/index"] [unique_id "amtxl3hIWorXRrZ1H1ywfwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-07-30 15:41:29
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
Ba-Yu
2026-07-30 15:27:04
(1 month ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-07-30 15:14:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 11:14:06.031637 2026] [security2:error] [pid 1665990:tid 1665990] [client 149.102.240.78:58192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ankitoner.com"] [uri "/.git/index"] [unique_id "amtqPhudWs50GPZ4Yn42jQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-07-30 14:56:20
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from UA.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from UA.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /.git/index
UA: moving-to-bins/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-30 14:55:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 10:55:46.685859 2026] [security2:error] [pid 3643609:tid 3643609] [client 149.102.240.78:57338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andrejblatnik.com"] [uri "/.git/index"] [unique_id "amtl8qrAH9DFc4dmOanv2gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-30 14:39:43
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.102.240.78 (unn-149-102-240-78.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 10:39:37.264379 2026] [security2:error] [pid 2182309:tid 2182309] [client 149.102.240.78:38898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ampstudio.eu"] [uri "/.git/index"] [unique_id "amtiKZoV0yI50x7yliN6PwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack