Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show moreAuto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.156.144.77 (BE/Belgium/77.144.156. ...
show more(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.156.144.77 (BE/Belgium/77.144.156.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
Anonymous
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
[TueJun0913:30:27.3192112026][security2:error][pid2837782:tid2837864][client34.156.144.77:0]ModSecur ...
show more[TueJun0913:30:27.3192112026][security2:error][pid2837782:tid2837864][client34.156.144.77:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.ilmiotrentino.it\"][uri\"/.git/config\"][unique_id\"aif5U8r2NAqQ94oz0zY7PgAAANA\"]
show less
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show moreTriggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.156.144.77 (BE/Belgium/77.144.15 ...
show moreLF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.156.144.77 (BE/Belgium/77.144.156.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
[TueJun0902:32:08.0682932026][security2:error][pid2550470:tid2550717][client34.156.144.77:0]ModSecur ...
show more[TueJun0902:32:08.0682932026][security2:error][pid2550470:tid2550717][client34.156.144.77:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.partnersat.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"aidfCPaRSGHBIJF9k60mTQAAAMQ\"]
show less
Hacking
Web App Attack
Showing 1 to
15
of 34 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ