🇺🇸
TPI-Abuse
2026-09-10 03:17:32
(24 minutes ago)
(mod_security) mod_security (id:210492) triggered by 198.251.85.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.251.85.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 23:17:24.465574 2026] [security2:error] [pid 25957:tid 25957] [client 198.251.85.131:36600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elgarage.com.mx"] [uri "/.git/config"] [unique_id "aqIhRAMJwgH8SIbABHiCGgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-09-10 03:07:41
(33 minutes ago)
[redacted] 198.251.85.131 - - [10/Sep/2026:04:07:40 +0100] "GET /.git/config HTTP/1.1" 302 6778 0/53 ...
show more
[redacted] 198.251.85.131 - - [10/Sep/2026:04:07:40 +0100] "GET /.git/config HTTP/1.1" 302 6778 0/53045 "-" "Mozilla/5.0 (X11; Linux x86_64)" [redacted] 198.251.85.131 - - [10/Sep/2026:04:07:40 +0100] "GET / HTTP/1.1" 200 9134 0/98822 "https://[redacted]/.git/config" "Mozilla/5.0 (X11; Linux x86_64)"
show less
Bad Web Bot
Web App Attack
🇳🇱
thedreamer.nl
2026-09-10 03:05:02
(36 minutes ago)
198.251.85.131 - - [10/Sep/2026:02:02:17 +0200] "GET /.git/config HTTP/1.1" 200 261 "-" "Mozilla/5.0 ...
show more
198.251.85.131 - - [10/Sep/2026:02:02:17 +0200] "GET /.git/config HTTP/1.1" 200 261 "-" "Mozilla/5.0 (X11; Linux x86_64)" "AU" "Sydney" "-33.86720" "151.19970"
198.251.85.131 - - [10/Sep/2026:04:05:21 +0200] "GET /.git/config HTTP/1.1" 404 123 "-" "Mozilla/5.0 (X11; Linux x86_64)" "AU" "Sydney" "-33.86720" "151.19970"
198.251.85.131 - - [10/Sep/2026:04:36:08 +0200] "GET /.git/config HTTP/1.1" 404 118 "-" "Mozilla/5.0 (X11; Linux x86_64)" "AU" "Sydney" "-33.86720" "151.19970"
198.251.85.131 - - [10/Sep/2026:05:03:18 +0200] "GET /.git/config HTTP/1.1" 401 0 "-" "Mozilla/5.0 (X11; Linux x86_64)" "AU" "Sydney" "-33.86720" "151.19970"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
JaRoNL
2026-09-10 03:04:29
(37 minutes ago)
198.251.85.131 - - [10/Sep/2026:05:04:28 +0200] "GET /.git/config HTTP/1.1" 404 7863 "-" "Mozilla/5. ...
show more
198.251.85.131 - - [10/Sep/2026:05:04:28 +0200] "GET /.git/config HTTP/1.1" 404 7863 "-" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
Charlesiv
2026-09-10 03:01:14
(40 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from AU.
Action taken: BLOCK
ASN: 14956 (RouterHosting LLC ...
show more
Triggered Cloudflare WAF (firewallCustom) from AU.
Action taken: BLOCK
ASN: 14956 (RouterHosting LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-09-10T01:55:03Z
Ray ID: a38aceed6a73cc7b
UA: Mozilla/5.0 (X11; Linux x86_64)
show less
Bad Web Bot
🇭🇺
kranem
2026-09-10 03:00:03
(41 minutes ago)
Triggered Cloudflare WAF from AU.
Action taken: BLOCK
ASN: 14956 (RouterHosting LLC)
Protocol: HTTP/ ...
show more
Triggered Cloudflare WAF from AU.
Action taken: BLOCK
ASN: 14956 (RouterHosting LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-09-10T02:42:35Z
User-Agent: Mozilla/5.0 (X11; Linux x86_64)
show less
Bad Web Bot
🇺🇸
jcbriar
2026-09-10 02:47:12
(54 minutes ago)
Searching for vulnerable scripts
Hacking
Web App Attack
🇫🇮
as211431.net
2026-09-10 02:42:37
(59 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from AU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from AU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (X11; Linux x86_64)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-10 02:41:57
(59 minutes ago)
(caddyscan) Scanner path probe from 198.251.85.131 (AU/Australia/-): 5 in the last 3600 secs; Ports: ...
show more
(caddyscan) Scanner path probe from 198.251.85.131 (AU/Australia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 404 217 198.251.85.131 - - [10/Sep/2026:02:16:58 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 198.251.85.131 - - [10/Sep/2026:02:17:14 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 404 224 198.251.85.131 - - [10/Sep/2026:02:35:47 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 404 216 198.251.85.131 - - [10/Sep/2026:02:36:40 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 198.251.85.131 - - [10/Sep/2026:02:41:53 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
🇮🇹
CoreTech srl
2026-09-10 02:38:56
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-10 04:34:10,359 fail2ban.filter [1892]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-10 04:34:10,359 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 136.144.19.13 - 2026-09-10 04:34:10cloudlinux2 fail2ban: 2026-09-10 04:34:35,336 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 106.214.9.78 - 2026-09-10 04:34:35cloudlinux2 fail2ban: 2026-09-10 04:35:50,080 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 106.214.9.78 - 2026-09-10 04:35:50cloudlinux2 fail2ban: 2026-09-10 04:36:00,626 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 106.214.9.78 - 2026-09-10 04:36:00cloudlinux2 fail2ban: 2026-09-10 04:36:00,727 fail2ban.filter [1892]: INFO [recidive] Found 106.214.9.78 - 2026-09-10 04:36:00cloudlinux2 fail2ban: 2026-09-10 04:36:00,726 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Ban 106.214.9.78cloudlinux2 fail2ban: 2026-09-10 04:36:18,641 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 23.94.155.24 - 2026-09-10 04:36:17cloudlinux2 fail2ban: 2026-09-10 04:36
show less
Web App Attack
Anonymous
2026-09-10 02:38:14
(1 hour ago)
[PathScanning] Path scanning/probing detected: Sensitive file access: Git repository; Source control ...
show more
[PathScanning] Path scanning/probing detected: Sensitive file access: Git repository; Source control directory probe (path: /.git/config) | [ForeignFrameworkProbe] Indiscriminate scan: probe for Git config disclosure on a CMS honeypot (path: /.git/config)
show less
Port Scan
Hacking
Web App Attack
🇫🇷
Catalin Negru
2026-09-10 02:37:44
(1 hour ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇺🇸
abuse-opdc
2026-09-10 02:16:02
(1 hour ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
🇷🇴
iulianh
2026-09-10 02:14:30
(1 hour ago)
80,443
Brute-Force
SSH
🇧🇪
boxed-it
2026-09-10 02:13:07
(1 hour ago)
GET /.git/config (Tarpitted for 5m48s, wasted 20.51kB)
Web App Attack