๐จ๐ญ
TheCoon
2026-06-10 07:45:02
(10 hours ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:02:46
(20 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 14:53:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:53:06.263230 2026] [security2:error] [pid 31246:tid 31246] [client 34.156.54.4:48782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vgalleria.vittariadesign.com"] [uri "/.git/config"] [unique_id "aigo0mix-7QfbaErH1hW0gAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 14:34:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:34:45.829768 2026] [security2:error] [pid 7389:tid 7389] [client 34.156.54.4:45402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bayinsights.com"] [uri "/.git/config"] [unique_id "aigkha-PFTLeJEZGigdNPAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-09 14:08:26
(1 day ago)
[TueJun0916:08:21.2677452026][security2:error][pid1411347:tid1412179][client34.156.54.4:0]ModSecurit ...
show more
[TueJun0916:08:21.2677452026][security2:error][pid1411347:tid1412179][client34.156.54.4:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpcalendars.cacciatorichiasso.ch\"][uri\"/.git/config\"][unique_id\"aigeVeFt1p463IoV7GMkvQAAAEw\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:30:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:30:37.835664 2026] [security2:error] [pid 28712:tid 28712] [client 34.156.54.4:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaitanyaconsult.in"] [uri "/.git/config"] [unique_id "aifrTfXazW7FKJblqdCVCAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-06-09 10:10:41
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Linux; Android 7.0; TRT-L21A) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 06:22:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:22:24.410398 2026] [security2:error] [pid 6680:tid 6680] [client 34.156.54.4:34010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dev.handyrehab.com"] [uri "/.git/config"] [unique_id "aiexIAI6qhritvPNIEw2jQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 03:53:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:53:04.862748 2026] [security2:error] [pid 22020:tid 22020] [client 34.156.54.4:43512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amatosdrywall.com"] [uri "/.git/config"] [unique_id "aieOIAe4TcVuN7WeujTXPgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Nexia
2026-06-09 03:46:26
(1 day ago)
[SENTINEL-HQ] Sentinel detected Critical Trap on /.git/config
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-09 00:40:49
(1 day ago)
[Tue Jun 09 10:40:48.453990 2026] [security2:error] [pid 173100] [client 34.156.54.4:59704] [client ...
show more
[Tue Jun 09 10:40:48.453990 2026] [security2:error] [pid 173100] [client 34.156.54.4:59704] [client 34.156.54.4] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.furst.com.au"] [uri "/.git/config"] [unique_id "aidhEDLIQDWE-mjcaz5WPQAAAAU"]
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:02:21
(1 day ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-08 20:52:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 16:52:36.410715 2026] [security2:error] [pid 14936:tid 14936] [client 34.156.54.4:33980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cbsproductionsinc.com"] [uri "/.git/config"] [unique_id "aicrlG5WsKfv8Uzs6vDdvwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 19:12:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:12:39.980151 2026] [security2:error] [pid 21262:tid 21262] [client 34.156.54.4:36316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.124projects.com"] [uri "/.git/config"] [unique_id "aicUJ_DrZm2l2quq4HzdUwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 18:56:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.54.4 (4.54.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 14:56:32.629666 2026] [security2:error] [pid 27629:tid 27629] [client 34.156.54.4:35358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hdeco.com.easternimport.com"] [uri "/.git/config"] [unique_id "aicQYBPXCArQY1JQC1pNGAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack