๐จ๐ญ
4server
2026-08-22 21:42:47
(22 hours ago)
[SatAug2223:42:43.0756422026][security2:error][pid11562:tid12322][client170.64.235.198:0]ModSecurity ...
show more
[SatAug2223:42:43.0756422026][security2:error][pid11562:tid12322][client170.64.235.198:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"gamotors.ch\"][uri\"/.git/config\"][unique_id\"aooX0-BxucmEmS_9aaezIAAAAYo\"]
show less
Hacking
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-22 19:30:46
(1 day ago)
[Sun Aug 23 05:30:45.788597 2026] [security2:error] [pid 321128] [client 170.64.235.198:46642] [clie ...
show more
[Sun Aug 23 05:30:45.788597 2026] [security2:error] [pid 321128] [client 170.64.235.198:46642] [client 170.64.235.198] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.git/config"] [unique_id "aon45ZMfdYIhk5x0x3_kCQAAAAE"]
...
show less
Web App Attack
๐ซ๐ท
ELYAZ
2026-08-22 19:02:11
(1 day ago)
(y3) Failed access -byebye- from 170.64.235.198 (AU/Australia/-): (CF_ENABLE)
Hacking
๐ง๐ท
dominioz
2026-08-22 17:42:16
(1 day ago)
2026-08-22 17:41:58 GET /.git/config - - 170.64.235.198 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+App ...
show more
2026-08-22 17:41:58 GET /.git/config - - 170.64.235.198 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 301 459
2026-08-22 17:42:00 GET /.git/config - - 170.64.235.198 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 301 554
2026-08-22 17:42:00 GET /.git/config - - 170.64.235.198 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 301 554
...
show less
Web App Attack
๐ช๐ธ
elcruzado.es
2026-08-22 16:29:23
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 170.64.235.198 (AU/Australia/-)
SQL Injection
๐ฉ๐ช
KiekerJan
2026-08-22 13:58:54
(1 day ago)
170.64.235.198 - - [22/Aug/2026:15:46:42 +0200] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 ...
show more
170.64.235.198 - - [22/Aug/2026:15:46:42 +0200] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
170.64.235.198 - - [22/Aug/2026:15:58:54 +0200] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-22 12:56:05
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 170.64.235.198 (AU/Australia/-): 1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 170.64.235.198 (AU/Australia/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
craudiovizai
2026-08-22 12:30:12
(1 day ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/config. Blocked a ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/config. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-08-22 10:57:39
(1 day ago)
PSCSERV WPSCAN 170.64.235.198
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-22 09:53:38
(1 day ago)
[Sat Aug 22 19:53:37.970311 2026] [security2:error] [pid 272919] [client 170.64.235.198:57292] [clie ...
show more
[Sat Aug 22 19:53:37.970311 2026] [security2:error] [pid 272919] [client 170.64.235.198:57292] [client 170.64.235.198] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.git/config"] [unique_id "aolxoZ9QF4AY0XRYrsOA2QAAAAM"]
...
show less
Web App Attack
๐ฉ๐ช
gadix
2026-08-22 09:42:05
(1 day ago)
[22/Aug/2026:08:58:08.926865 +0200] aolIf8JCc_BPkanVHEH1XgAAAAw 170.64.235.198 39524 127.0.0.1 7081
...
show more
[22/Aug/2026:08:58:08.926865 +0200] aolIf8JCc_BPkanVHEH1XgAAAAw 170.64.235.198 39524 127.0.0.1 7081
[22/Aug/2026:11:15:32.460221 +0200] aolotBe2ZkzzHKXbyLOZxAAAAAc 170.64.235.198 35672 127.0.0.1 7081
[22/Aug/2026:11:42:04.081851 +0200] aolu61PtaxjBzZDSN0pyXQAAAAE 170.64.235.198 51546 127.0.0.1 7081
...
show less
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-22 09:03:06
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from AU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from AU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-22 06:44:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.235.198 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.235.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:44:39.849091 2026] [security2:error] [pid 25016:tid 25016] [client 170.64.235.198:43098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starrmail.net"] [uri "/.git/config"] [unique_id "aolFV1nOhbCrwQfTIBD4_QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-08-22 05:18:14
(1 day ago)
2026-08-22 01:37:40 GET /.git/config - - 170.64.235.198 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+App ...
show more
2026-08-22 01:37:40 GET /.git/config - - 170.64.235.198 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 301 459
2026-08-22 01:37:42 GET /.git/config - - 170.64.235.198 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 301 554
2026-08-22 05:17:24 GET /.git/config - - 170.64.235.198 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 301 459
2026-08-22 05:17:26 GET /.git/config - - 170.64.235.198 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 301 554
...
show less
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-22 05:14:52
(1 day ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking