🇲🇽
octageeks.com
2026-09-10 04:18:58
(9 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇫🇷
service Informatique
2026-09-10 04:00:37
(10 hours ago)
/.git
Web App Attack
🇺🇸
wbsouza
2026-09-10 03:26:50
(10 hours ago)
CrowdSec: infra/bad-path-probe — automated firewall drops on self-hosted IDS sensor
Hacking
Anonymous
2026-09-09 23:30:03
(14 hours ago)
Blocked by os-abuseipdb; 5 hits, proto=tcp, ports=443
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-09 23:29:20
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.86.74.224 (224.74.86.172.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.74.224 (224.74.86.172.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 19:29:14.531605 2026] [security2:error] [pid 23892:tid 23892] [client 172.86.74.224:50834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "salazartransfers.com"] [uri "/.git/config"] [unique_id "aqHryralYcxSg3M0iuz9fAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇬
pa4080
2026-09-09 22:47:48
(15 hours ago)
Detected by ModSecurity. Request URI: /.git/config
Web App Attack
🇫🇮
as211431.net
2026-09-09 22:42:54
(15 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (X11; Linux x86_64)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇫🇷
omartin
2026-09-09 22:36:07
(15 hours ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-09-09 22:19:42
(15 hours ago)
(caddyscan) Scanner path probe from 172.86.74.224 (US/United States/224.74.86.172.static.cloudzy.com ...
show more
(caddyscan) Scanner path probe from 172.86.74.224 (US/United States/224.74.86.172.static.cloudzy.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 404 216 172.86.74.224 - - [09/Sep/2026:21:45:57 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.86.74.224 - - [09/Sep/2026:21:55:41 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.86.74.224 - - [09/Sep/2026:21:58:41 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.86.74.224 - - [09/Sep/2026:22:18:54 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.86.74.224 - - [09/Sep/2026:22:19:40 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
🇳🇱
JaRoNL
2026-09-09 22:11:55
(15 hours ago)
172.86.74.224 - - [10/Sep/2026:00:11:54 +0200] "GET /.git/config HTTP/1.1" 404 7864 "-" "Mozilla/5.0 ...
show more
172.86.74.224 - - [10/Sep/2026:00:11:54 +0200] "GET /.git/config HTTP/1.1" 404 7864 "-" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
joharikop
2026-09-09 21:49:51
(16 hours ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 20:56:33
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.86.74.224 (224.74.86.172.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.74.224 (224.74.86.172.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 16:56:27.701417 2026] [security2:error] [pid 16880:tid 16880] [client 172.86.74.224:45822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fanarch.xyz"] [uri "/.git/config"] [unique_id "aqHH-2UMHfOMwphWw69oUQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 20:35:33
(17 hours ago)
(caddyscan) Scanner path probe from 172.86.74.224 (US/United States/224.74.86.172.static.cloudzy.com ...
show more
(caddyscan) Scanner path probe from 172.86.74.224 (US/United States/224.74.86.172.static.cloudzy.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.86.74.224 - - [09/Sep/2026:19:38:51 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 404 221 172.86.74.224 - - [09/Sep/2026:20:01:43 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.86.74.224 - - [09/Sep/2026:20:01:52 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.86.74.224 - - [09/Sep/2026:20:10:51 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.86.74.224 - - [09/Sep/2026:20:35:31 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-09 20:16:04
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.86.74.224 (224.74.86.172.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.74.224 (224.74.86.172.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 16:15:58.589692 2026] [security2:error] [pid 4485:tid 4485] [client 172.86.74.224:54170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ropesandsneakers.com.flatchestedmama.com"] [uri "/.git/config"] [unique_id "aqG-fq6HMrwiSoGP6efouAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hagen Schoebel
2026-09-09 20:11:52
(17 hours ago)
Blocked by CrowdSec - anomaly score block: lfi: 5, anomaly: 5, (US)
Port Scan
Brute-Force
Web App Attack
SSH