๐บ๐ธ
TPI-Abuse
2026-07-27 15:37:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:37:00.866869 2026] [security2:error] [pid 20666:tid 20666] [client 3.249.156.73:56332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.robtown.com"] [uri "/.git/config"] [unique_id "amd7HL7deukkfnB6q3-o-gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 10:37:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:36:56.004008 2026] [security2:error] [pid 3282379:tid 3282379] [client 3.249.156.73:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ralphrichardson.com"] [uri "/.env.txt"] [unique_id "amc0yFPGWeT5SHuUqvn5hgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:45:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:45:11.539442 2026] [security2:error] [pid 3401013:tid 3401013] [client 3.249.156.73:37074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.progressivefileshare.org"] [uri "/.git/config"] [unique_id "ambwZ1Ak_yUAnB4Ehlcf9wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-27 05:35:03
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:18:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:18:50.644963 2026] [security2:error] [pid 1399799:tid 1399827] [client 3.249.156.73:58424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.priyom.us"] [uri "/.git/config"] [unique_id "ambqOojs1wqz23XpIB-6XQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 02:10:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 22:10:38.845214 2026] [security2:error] [pid 2455471:tid 2455471] [client 3.249.156.73:34828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "curriergallery.com"] [uri "/.git/config"] [unique_id "amVsnnH4xesCiLL8wycPXQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
1gz
2026-07-26 02:07:06
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from IE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from IE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-25 05:29:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 01:29:32.643253 2026] [security2:error] [pid 12265:tid 12265] [client 3.249.156.73:44696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.fairfieldfarms.net"] [uri "/.git/config"] [unique_id "amRJvPIqU2zsDqXZOBsmWQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 05:05:34
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.156.73 (ec2-3-249-156-73.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:05:29.419806 2026] [security2:error] [pid 3422319:tid 3422319] [client 3.249.156.73:60666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.frenosilent.ar"] [uri "/.git/config"] [unique_id "amLymaRAOm0Gu7BewxGwDgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 04:35:04
(4 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack