π΅π±
MatStef132
2026-08-29 22:32:31
(16 hours ago)
MatShield L7: blocked on api.klovy.chat (ua-quarantined)
Bad Web Bot
π§π¬
Stoyko Stoykov
2026-08-29 03:20:19
(1 day ago)
172.68.245.217 - - [29/Aug/2026:06:20:16 +0300] "GET /.env.dev HTTP/1.1" 301 162 "-" "crusader-worke ...
show more
172.68.245.217 - - [29/Aug/2026:06:20:16 +0300] "GET /.env.dev HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 13:30:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 09:30:38.852456 2026] [security2:error] [pid 5794:tid 5794] [client 172.68.245.217:12771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mac136.org"] [uri "/.git/HEAD"] [unique_id "aoMM_l6qbzHPuq1LvAKllwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 12:11:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 08:11:13.672994 2026] [security2:error] [pid 10806:tid 10806] [client 172.68.245.217:11346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jeremy-olson.com"] [uri "/.git/config"] [unique_id "aoL6YT4ikRfUFG2SPOerzQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 10:44:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:44:44.857864 2026] [security2:error] [pid 18786:tid 18786] [client 172.68.245.217:11792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.13waggoners.com"] [uri "/.git/config"] [unique_id "aoLmHDf4ovQlXOgPB6ifQAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 09:10:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:10:02.486381 2026] [security2:error] [pid 15792:tid 15792] [client 172.68.245.217:10971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rokket.com"] [uri "/.git/HEAD"] [unique_id "aoLP6hKunu5HaGjS1Mas_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 11:08:25
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 07:08:18.333061 2026] [security2:error] [pid 25080:tid 25080] [client 172.68.245.217:11511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.willowgrovemusic.com"] [uri "/.git/config"] [unique_id "aoGaIrshi6q3YVqXiSkNAAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 08:42:36
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:42:31.548998 2026] [security2:error] [pid 21496:tid 21496] [client 172.68.245.217:11300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thresholddigital.hal.dance"] [uri "/.git/config"] [unique_id "aoF395BZomkf1AP6Qz4qjgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 04:45:32
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 00:45:27.427864 2026] [security2:error] [pid 5751:tid 5835] [client 172.68.245.217:12515] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tsengkwongchi.com"] [uri "/.git/config"] [unique_id "aoFAZ8IL2RneyCUzHUWBlAAAAZI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 20:26:52
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:26:45.204939 2026] [security2:error] [pid 3559:tid 3559] [client 172.68.245.217:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.webuildbeaches.com"] [uri "/app/config/parameters.yml"] [unique_id "ainIhb6W1WreejHTHouDmwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
pinguin
2026-06-04 08:35:49
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π©πͺ
acadeova
2026-05-29 08:29:49
(3 months ago)
π¨ Recon detected (nft drop)
SRC=172.68.245.217
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
π¨ Recon detected (nft drop)
SRC=172.68.245.217
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-05-25 14:01:44
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 10:01:37.530108 2026] [security2:error] [pid 5652:tid 5652] [client 172.68.245.217:13625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamescreates.org"] [uri "/app/config/parameters.yml"] [unique_id "ahRWQVHQsyhymDv5_GuIfwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
oncord
2026-05-15 03:51:36
(3 months ago)
Form spam
Web Spam
π¦πΊ
oncord
2026-04-14 06:44:24
(4 months ago)
Form spam
Web Spam