๐ง๐ช
madeit
2026-08-17 19:54:22
(1 week ago)
Web App Attack
๐ณ๐ฟ
FaB Property Group
2026-08-17 13:38:15
(1 week ago)
Requested file: .git/head
Web App Attack
๐ณ๐ฟ
FaB Property Group
2026-08-17 13:38:15
(1 week ago)
Requested file: .git/head
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:10:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:09:53.889720 2026] [security2:error] [pid 14331:tid 14331] [client 172.71.195.97:10934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.webmail.bendergloves.com"] [uri "/.git/HEAD"] [unique_id "aoLP4aGE2z2CI9eHAJQLpwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:11:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:11:12.276931 2026] [security2:error] [pid 20230:tid 20230] [client 172.71.195.97:14127] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.krugmans.org"] [uri "/.git/config"] [unique_id "aoKmAJd6XJUY3jamekHW1gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:21:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:21:32.848466 2026] [security2:error] [pid 30200:tid 30200] [client 172.71.195.97:13412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.zztp.ws"] [uri "/.git/HEAD"] [unique_id "aoEsvHlj3v6K1v_FTqfe3gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 18:08:49
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 14:08:44.481743 2026] [security2:error] [pid 3823295:tid 3823295] [client 172.71.195.97:11440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.madbanana.com"] [uri "/.git/config"] [unique_id "antlLLsLwLf_4S9mC0BXXQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 03:07:29
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 23:07:22.723165 2026] [security2:error] [pid 3728627:tid 3728627] [client 172.71.195.97:12730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tupansetc.com"] [uri "/.git/config"] [unique_id "anqR6rND5nBQ3te5NEdKNwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-08-09 18:56:28
(2 weeks ago)
๐จ Recon detected (nft drop)
SRC=172.71.195.97
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.71.195.97
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฌ๐ง
pinguin
2026-08-06 19:36:13
(2 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /@fs/var/www/.env
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ช
madeit
2026-08-06 00:20:34
(2 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:18:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:17:41.711438 2026] [security2:error] [pid 3856:tid 3856] [client 172.71.195.97:13599] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shelbynash.com"] [uri "/.env.local"] [unique_id "agbktdqZF3Khkf1VtV_cDAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:01:20
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:01:12.250225 2026] [security2:error] [pid 26106:tid 26119] [client 172.71.195.97:10479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sellmantitle.com"] [uri "/app/config/parameters.yml"] [unique_id "agbEuJnS8FEBI5_YA54MnwAAAUg"], referer: https://www.google.com/search?q=sellmantitle.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 21:02:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.195.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 17:01:56.387113 2026] [security2:error] [pid 8315:tid 8315] [client 172.71.195.97:9498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "summitartists.com"] [uri "/.git/config"] [unique_id "af-gxPxIxt5wGXhfEv21iAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-21 22:00:52
(4 months ago)
Auto-ban: >3000 req/min op 2026-04-21
Web App Attack
SSH
Hacking