๐ซ๐ฎ
as211431.net
2026-09-20 06:37:44
(9 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/HEAD
UA: Python-urllib/3.10
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-09-19 21:59:18
(18 hours ago)
Auto-ban: >3000 req/min op 2026-09-19
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 13:50:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 09:50:40.868914 2026] [security2:error] [pid 9772:tid 9772] [client 172.245.193.97:36517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "macryder.com"] [uri "/.git/HEAD"] [unique_id "aq6TMH9roY1llh1tKE6aoAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 19:43:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 15:42:16.756291 2026] [security2:error] [pid 6008:tid 6147] [client 172.245.193.97:56377] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.southerncalifornia.aafm.us"] [uri "/.git/HEAD"] [unique_id "aq2UGJv0YynBFetnvKP1WQAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 22:31:47
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 18:31:40.875003 2026] [security2:error] [pid 25196:tid 25196] [client 172.245.193.97:41763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.papapizza.pizza"] [uri "/.git/HEAD"] [unique_id "aqh1zCueJp3lAb0805mOfAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 18:34:15
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 14:34:11.950063 2026] [security2:error] [pid 11042:tid 11087] [client 172.245.193.97:58340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.destination-kitchen.com"] [uri "/.git/HEAD"] [unique_id "aqg-I4POMyHb5Yv6ZvtGwwAAAcI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 11:09:52
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 07:09:42.300687 2026] [security2:error] [pid 27619:tid 27619] [client 172.245.193.97:43140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kmp.net"] [uri "/.git/HEAD"] [unique_id "aqfV9opi157aWL68sRWddQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-14 06:26:18
(6 days ago)
[14/Sep/2026:09:26:18 +0300] -- 172.245.193.97 Ban reason: User-Agent Python-urllib
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 01:32:50
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 21:32:43.030838 2026] [security2:error] [pid 3125:tid 3125] [client 172.245.193.97:52333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jolka.org"] [uri "/.git/HEAD"] [unique_id "aqdOu8ehm5pLNQSvhPb5kAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 22:07:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:07:44.017722 2026] [security2:error] [pid 22439:tid 22439] [client 172.245.193.97:45213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.accordionclub.org"] [uri "/.git/HEAD"] [unique_id "aqXNMKjHdwYqVjnxYqVKrwAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 18:20:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 14:20:23.262914 2026] [security2:error] [pid 10732:tid 10732] [client 172.245.193.97:39217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.effectivefirearms.com"] [uri "/.git/HEAD"] [unique_id "aqWX552SihZCayItxWOGZQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 12:40:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:39:55.453991 2026] [security2:error] [pid 6984:tid 6984] [client 172.245.193.97:60670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.frenosilent.net.ar"] [uri "/.git/HEAD"] [unique_id "aqVIGzGqQ5_cypq_QPraAQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-12 12:10:41
(1 week ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/HEAD | 2026-09-12 12:10 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 09:37:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 172.245.193.97 (172-245-193-97-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:37:08.871855 2026] [security2:error] [pid 15488:tid 15488] [client 172.245.193.97:39947] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.register-yacht-delaware.com"] [uri "/.git/HEAD"] [unique_id "aqUdRHleh_8M_OcidAEKngAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-11 20:25:27
(1 week ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.245.193.97 (US/United States/17 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 172.245.193.97 (US/United States/172-245-193-97-host.colocrossing.com): 1 in the last 3600 secs
show less
Web App Attack