๐บ๐ธ
TPI-Abuse
2026-09-12 22:08:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:07:43.987662 2026] [security2:error] [pid 22449:tid 22449] [client 198.144.187.99:41875] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.accordionfactory.com.accordionclub.org"] [uri "/.git/HEAD"] [unique_id "aqXNLwO5b3MFO7vzQVmrjgAAAFk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 21:07:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:07:02.972021 2026] [security2:error] [pid 2167775:tid 2167861] [client 198.144.187.99:50526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.theworldinstituteofslowness.com"] [uri "/.git/HEAD"] [unique_id "aqW-9mKWZNIAO1vIl76goAAAAdY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 18:42:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 14:42:49.636188 2026] [security2:error] [pid 15077:tid 15077] [client 198.144.187.99:55103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.accommodation-perthairport.com"] [uri "/.git/HEAD"] [unique_id "aqWdKRLEQtm9s_ZxBSTGhQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 18:10:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 14:10:20.104886 2026] [security2:error] [pid 27106:tid 27106] [client 198.144.187.99:46102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.russiacoin.info"] [uri "/.git/HEAD"] [unique_id "aqWVjDM1tr3dGEtD26AIJwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-11 17:02:17
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 14:35:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 10:35:38.836423 2026] [security2:error] [pid 18667:tid 18667] [client 198.144.187.99:37169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frenosilent.net.ar"] [uri "/.git/HEAD"] [unique_id "aqQRuugLH5LuNlzc5SMFrQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-11 08:07:01
(1 week ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,wa02]
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-11 07:08:01
(1 week ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice02,mx02,wa01]
Bad Web Bot
Web App Attack
๐บ๐ธ
billyw0nka
2026-09-10 23:46:57
(1 week ago)
pattern: .git
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-10 18:29:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 14:29:34.893183 2026] [security2:error] [pid 4579:tid 4579] [client 198.144.187.99:34999] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brandoncomputergeeks.com"] [uri "/.git/HEAD"] [unique_id "aqL3DlwQLHyV_X-PXX5UAgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-08 11:39:54
(2 weeks ago)
Accessed trap at '/.git/HEAD'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 11:03:48
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossin ...
show more
(mod_security) mod_security (id:210492) triggered by 198.144.187.99 (198-144-187-99-host.colocrossing.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:03:42.261151 2026] [security2:error] [pid 3517:tid 3517] [client 198.144.187.99:41291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lynnsmetkodesigns.com"] [uri "/.git/HEAD"] [unique_id "ap_rjludNrguq18EoUJ6nAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-08 10:30:16
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/HEAD | UA: Python-urllib/3.10 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ฉ
origrata
2026-09-06 09:20:08
(2 weeks ago)
[OGWAF] path_traversal attack blocked | severity: high | GET /.git/HEAD | UA: Python-urllib/3.10
Hacking
Web App Attack
๐ฌ๐ง
pinguin
2026-09-05 22:01:27
(2 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/HEAD
UA: Python-urllib/3.10
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot