๐ฉ๐ช
David Ferneding
2026-10-02 02:36:48
(36 minutes ago)
Blocked by UFW (TCP on 80)
Source port: 43086
TTL: 55
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 43086
TTL: 55
Packet length: 60
TOS: 0x00
This report (for 159.223.186.220) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐ฎ๐ฉ
origrata
2026-10-02 01:37:53
(1 hour ago)
[OGWAF] path_traversal attack blocked | severity: high | GET /.git/config | UA: Mozilla/5.0 (X11; Li ...
show more
[OGWAF] path_traversal attack blocked | severity: high | GET /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/5
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 01:20:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 159.223.186.220 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.186.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:20:06.872819 2026] [security2:error] [pid 22427:tid 22433] [client 159.223.186.220:37838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "halescreations.com"] [uri "/.git/config"] [unique_id "ar8Gxo4-LDos3Y7EVgIRTAAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-01 21:59:27
(5 hours ago)
Auto-ban: >3000 req/min op 2026-10-01
Web App Attack
SSH
Hacking
๐บ๐ธ
mnsf
2026-10-01 19:05:45
(8 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:58:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 159.223.186.220 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.186.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:58:56.005782 2026] [security2:error] [pid 20764:tid 20833] [client 159.223.186.220:54672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smarterproductions.com"] [uri "/.git/config"] [unique_id "ar6fYJf3t-TzlYVejfu0YAAAAcw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:28:33
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 159.223.186.220 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.186.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:28:27.150194 2026] [security2:error] [pid 23449:tid 23449] [client 159.223.186.220:44782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jesusthechristministry.org"] [uri "/.git/config"] [unique_id "ar6YO2hZ51N_0qq5MBquiAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:39:58
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 159.223.186.220 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.186.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:39:52.045435 2026] [security2:error] [pid 4064:tid 4064] [client 159.223.186.220:59814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "studioyau.com"] [uri "/.git/config"] [unique_id "ar6M2A9epVWnARQedXeQywAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:04:24
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 159.223.186.220 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.186.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:04:16.628729 2026] [security2:error] [pid 26849:tid 26901] [client 159.223.186.220:38072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreammile.info"] [uri "/.git/config"] [unique_id "ar6EgJT9dzagRvUoxm0YYwAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-10-01 16:02:26
(11 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
MM-bot
2026-10-01 15:38:25
(11 hours ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-10-01 17:38:25 UTC+2)
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-10-01 14:59:02
(12 hours ago)
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 15 ...
show more
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 159.223.186.220 - - [01/Oct/2026:16:59:02 +0200] "GET /.git/config HTTP/1.1" 301 571 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ฆ
Olexiy Backend
2026-10-01 14:51:02
(12 hours ago)
159.223.186.220
...
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 14:28:01
(12 hours ago)
[ti-03tr] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-03tr] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 159.223.186.220 - - [01/Oct/2026:16:28:00 +0200] "GET /.git/config HTTP/1.1" 404 9047 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-01 14:10:22
(13 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-10-01T12:54:08Z
Ray ID: a43b9d3c29d63e9d
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
show less
Bad Web Bot