๐ณ๐ด
jad-abuse
2026-07-19 09:06:04
(4 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-19 09:05:48
(4 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐ณ๐ฑ
ipoac.nl
2026-07-19 09:01:26
(4 days ago)
-:443 34.6.103.15 - - [19/Jul/2026:11:01:25 +0200] - "GET /.git/config HTTP/1.1" 404 7414 "-" "Mozil ...
show more
-:443 34.6.103.15 - - [19/Jul/2026:11:01:25 +0200] - "GET /.git/config HTTP/1.1" 404 7414 "-" "Mozilla/5.0 (X11; Linux x86_64)"
show less
Bad Web Bot
๐ต๐ฑ
sefinek.net
2026-07-19 08:51:45
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-19 08:51:10
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.6.103.15 (15.103.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.103.15 (15.103.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 04:51:03.087834 2026] [security2:error] [pid 5761:tid 5761] [client 34.6.103.15:44188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natesupport.com.techsunlimited.net"] [uri "/.git/config"] [unique_id "alyP98dX82L0wt-HFSTVFAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Donovan
2026-07-19 08:50:12
(4 days ago)
Web scan/exploit blocked by fail2ban on commitshift.fr - jail: npm-scan - 1 attempt(s)
Web App Attack
๐บ๐ธ
CBJ
2026-07-19 08:42:25
(4 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
Major Hostility
2026-07-19 08:42:06
(4 days ago)
"GET /.git/config HTTP/1.1" 404
"GET /.git/config HTTP/1.1" 404
Web App Attack
๐ซ๐ท
dynamix
2026-07-19 08:41:51
(4 days ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
MatStef132
2026-07-19 08:38:56
(4 days ago)
MatShield L7: blocked on mathost.eu (secret-path-probe)
DDoS Attack
๐ซ๐ฎ
as211431.net
2026-07-19 08:37:41
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (X11; Linux x86_64)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-19 08:35:12
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.6.103.15 (15.103.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.103.15 (15.103.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 04:35:09.500550 2026] [security2:error] [pid 16680:tid 16680] [client 34.6.103.15:43988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.paulschuster.com"] [uri "/.git/config"] [unique_id "alyMPVWulNARbgtKkF8HwgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
daveoctober
2026-07-19 08:17:56
(4 days ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 08:12:02
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.6.103.15 (15.103.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.103.15 (15.103.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 04:11:56.197129 2026] [security2:error] [pid 22591:tid 22591] [client 34.6.103.15:56820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crystaljohns.com.my-spec.com"] [uri "/.git/config"] [unique_id "alyGzLM6k7cDChDD2brUfAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-19 08:05:03
(4 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack