๐ฎ๐ณ
evicky2002
2026-07-30 06:00:00
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-29 22:29:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.178.20 (20.178.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.178.20 (20.178.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 18:29:27.832692 2026] [security2:error] [pid 2473421:tid 2473421] [client 34.23.178.20:45380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tipdavid.com"] [uri "/.git/config"] [unique_id "amp-x92gFJeTlCzUKqun5gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
kie
2026-07-29 22:04:42
(1 day ago)
29-07-2026:22:03:54UTC [Nginx Web Server] Suspicious web request: path:/.git (1 request(s)).
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-07-29 21:51:26
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฆ๐บ
Klaverstyn
2026-07-29 21:51:10
(1 day ago)
Repeated 403 Forbidden responses
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 21:47:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.178.20 (20.178.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.178.20 (20.178.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 17:47:17.357851 2026] [security2:error] [pid 1471556:tid 1471621] [client 34.23.178.20:42058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.easygifting.com.williampower.com"] [uri "/.git/config"] [unique_id "amp05XQggEjwUGmPSxRRMAAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 21:20:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.178.20 (20.178.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.178.20 (20.178.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 17:20:51.484882 2026] [security2:error] [pid 18609:tid 18609] [client 34.23.178.20:59302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prospayinsulation.com.savingshvac.com"] [uri "/.git/config"] [unique_id "ampus2wDp79w7cgnk0C00QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 20:41:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.178.20 (20.178.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.178.20 (20.178.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 16:40:58.728592 2026] [security2:error] [pid 1125612:tid 1125612] [client 34.23.178.20:33726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flickr.abecasis.com"] [uri "/.git/config"] [unique_id "amplWh1ym7JoGMEKffsGrwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
langenkamp-media
2026-07-29 20:39:33
(1 day ago)
Fail2Ban: Banned from jail nginx-scan-critical on 3dausdu.de
Web App Attack
๐ฌ๐ง
Oakley
2026-07-29 20:37:03
(1 day ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐ฉ๐ช
Ba-Yu
2026-07-29 20:25:17
(1 day ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 20:19:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.178.20 (20.178.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.178.20 (20.178.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 16:18:59.090386 2026] [security2:error] [pid 17915:tid 17947] [client 34.23.178.20:43918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mysticscon.com"] [uri "/.git/config"] [unique_id "ampgM4S7Fj6WQ3yCpysW3QAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hagen Schoebel
2026-07-29 20:08:52
(1 day ago)
Blocked by CrowdSec - anomaly score block: lfi: 5, anomaly: 5, (US)
Port Scan
Brute-Force
Web App Attack
SSH
๐ซ๐ท
mail.avx.gr
2026-07-29 20:07:02
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 34.23.178.20 - - [29/Jul/202 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 34.23.178.20 - - [29/Jul/2026:23:07:01 +0300] "GET /.git/config HTTP/1.1" 403 2428 "-" "-"
show less
Web App Attack
๐บ๐ธ
Charlesiv
2026-07-29 20:00:49
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-07-29T18:03:46Z
Ray ID: a22e0ad0ce071f6b
UA: Empty string
show less
Bad Web Bot