🇺🇸
TPI-Abuse
2026-09-12 22:08:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:07:44.005708 2026] [security2:error] [pid 21385:tid 21385] [client 196.247.18.212:55577] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.concertoaccordion.accordionclub.org"] [uri "/.git/HEAD"] [unique_id "aqXNMLT8OwBusS44yvsV0QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:16:35
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:16:31.659068 2026] [security2:error] [pid 18509:tid 18509] [client 196.247.18.212:34446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.brandfacets.com"] [uri "/.git/HEAD"] [unique_id "aqUYb28jxRl8iyWJNU0cbQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 08:51:10
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:51:05.932901 2026] [security2:error] [pid 30593:tid 30593] [client 196.247.18.212:39326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.frenosilent.net.ar"] [uri "/.git/HEAD"] [unique_id "aqUSeV7VyPIcWuMvKkihuQAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 19:56:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:56:22.177932 2026] [security2:error] [pid 29032:tid 29032] [client 196.247.18.212:49831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.aquatreat.net"] [uri "/.git/HEAD"] [unique_id "aqRc5p7XmRRk7elzlY91cQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 02:33:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:33:16.084539 2026] [security2:error] [pid 16490:tid 16490] [client 196.247.18.212:37403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.coloradofingerprinting.com"] [uri "/.git/HEAD"] [unique_id "aqNobF4A1_sQwaidcNSv_AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:56:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:56:27.667733 2026] [security2:error] [pid 8739:tid 8739] [client 196.247.18.212:55308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gumsandimplants.com"] [uri "/.git/HEAD"] [unique_id "aqCuu6g7RmjlKVr863gX_gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 19:00:09
(4 days ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-09-08 17:09:30
(4 days ago)
GET /.git/HEAD HTTP/1.1
...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 11:07:52
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 07:07:40.529440 2026] [security2:error] [pid 13556:tid 13556] [client 196.247.18.212:52146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.totalstorage.solutions"] [uri "/.git/HEAD"] [unique_id "ap1JfKcllo9aIYS0zXc3bAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
pinguin
2026-09-05 22:01:27
(1 week ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/HEAD
UA: Python-urllib/3.10
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇳🇱
BlueWire Hosting
2026-09-05 01:37:34
(1 week ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 00:47:58
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 20:47:51.253738 2026] [security2:error] [pid 20862:tid 20862] [client 196.247.18.212:33082] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "manavamooreabookings.com"] [uri "/.git/HEAD"] [unique_id "aptmt6xommL6lUV0xUxOOQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-05 00:08:57
(1 week ago)
cloudlinux2 fail2ban: 2026-09-05 02:05:20,024 fail2ban.filter [1594]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-05 02:05:20,024 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.146.55.215 - 2026-09-05 02:05:19cloudlinux2 fail2ban: 2026-09-05 02:05:24,410 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.146.55.215 - 2026-09-05 02:05:24cloudlinux2 fail2ban: 2026-09-05 02:05:20,314 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.146.55.182 - 2026-09-05 02:05:19cloudlinux2 fail2ban: 2026-09-05 02:05:51,122 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 136.144.42.68 - 2026-09-05 02:05:50cloudlinux2 fail2ban: 2026-09-05 02:05:54,620 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 188.3.218.195 - 2026-09-05 02:05:54cloudlinux2 fail2ban: 2026-09-05 02:06:46,009 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.46 - 2026-09-05 02:06:45cloudlinux2 fail2ban: 2026-09-05 02:06:54,101 fail2ban.actions [1594]: NOTICE [plesk-wordpress] Unban 193.56.116.85cloudlinux2 fail2ban: 2026-09
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:48:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.247.18.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:46:56.112718 2026] [security2:error] [pid 14117:tid 14135] [client 196.247.18.212:36766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.certifiedmanagementaccountant.org.aafm.us"] [uri "/.git/HEAD"] [unique_id "apsgMJogtjmLlKhyltjm7wAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack