Anonymous
2026-08-28 04:33:15
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ง๐ช
Ivo Vynckier
2026-08-24 09:38:00
(4 days ago)
170.64.203.86 - - [23/Aug/2026:19:32:14 +0200] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 ...
show more
170.64.203.86 - - [23/Aug/2026:19:32:14 +0200] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-24 05:14:16
(5 days ago)
6 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-08-23 22:01:03
(5 days ago)
Auto-ban: >3000 req/min op 2026-08-23
Web App Attack
SSH
Hacking
๐ซ๐ท
masterguru
2026-08-23 18:00:45
(5 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-08-23 17:59:34
(5 days ago)
(caddyscan) Scanner path probe from 170.64.203.86 (AU/Australia/-): 5 in the last 3600 secs; Ports: ...
show more
(caddyscan) Scanner path probe from 170.64.203.86 (AU/Australia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 170.64.203.86 - - [23/Aug/2026:17:28:18 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 404 230 170.64.203.86 - - [23/Aug/2026:17:32:12 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 170.64.203.86 - - [23/Aug/2026:17:40:04 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 170.64.203.86 - - [23/Aug/2026:17:55:52 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 170.64.203.86 - - [23/Aug/2026:17:59:31 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐ฆ๐บ
paulshipley.com.au
2026-08-23 16:06:59
(5 days ago)
[Mon Aug 24 02:06:58.788237 2026] [security2:error] [pid 441331] [client 170.64.203.86:35020] [clien ...
show more
[Mon Aug 24 02:06:58.788237 2026] [security2:error] [pid 441331] [client 170.64.203.86:35020] [client 170.64.203.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.git/config"] [unique_id "aosaolyGH4JH7c4tNJw4qQAAAAM"]
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-08-23 15:28:39
(5 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-23 15:16:26
(5 days ago)
Multiple WAF Violations
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-23 14:03:01
(5 days ago)
[Mon Aug 24 00:03:00.202676 2026] [security2:error] [pid 430728] [client 170.64.203.86:43804] [clien ...
show more
[Mon Aug 24 00:03:00.202676 2026] [security2:error] [pid 430728] [client 170.64.203.86:43804] [client 170.64.203.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.git/config"] [unique_id "aor9lBWL8myEUWWSyOS3-gAAAAU"]
...
show less
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-08-23 13:36:08
(5 days ago)
170.64.203.86 - - [23/Aug/2026:07:36:07 -0600] "GET /.git/config HTTP/1.1" 301 487 "-" "Mozilla/5.0 ...
show more
170.64.203.86 - - [23/Aug/2026:07:36:07 -0600] "GET /.git/config HTTP/1.1" 301 487 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-08-23 12:03:56
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.top | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-23 11:34:10
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from AU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from AU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-23 11:15:29
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 170.64.203.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.203.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:15:23.484220 2026] [security2:error] [pid 15826:tid 15826] [client 170.64.203.86:56730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kidswow.net"] [uri "/.git/config"] [unique_id "aorWSwWtD7ap8iG_IxXalAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 10:45:03
(5 days ago)
Unauthorized SSH login attempts
Brute-Force
SSH