๐ง๐ท
Peregrine
2026-06-12 03:13:22
(18 hours ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.73.31.183 108.162.237.153 - - [08/Jun/2026:23:04 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.73.31.183 108.162.237.153 - - [08/Jun/2026:23:04:49 -0300] "GET /.git/config HTTP/1.1" 404 18193
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-06-10 22:00:13
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-09.
show less
Web App Attack
SSH
Hacking
๐ง๐ท
Peregrine
2026-06-10 03:14:01
(2 days ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.73.31.183 108.162.237.153 - - [08/Jun/2026:23:04 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.73.31.183 108.162.237.153 - - [08/Jun/2026:23:04:49 -0300] "GET /.git/config HTTP/1.1" 404 18193
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 16:20:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 12:20:39.267273 2026] [security2:error] [pid 26959:tid 26959] [client 34.73.31.183:39404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thomasmichaelrussell.com"] [uri "/.git/config"] [unique_id "aig9V_Ae4lSaIx6ucm3fcgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 15:28:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:28:52.927050 2026] [security2:error] [pid 29103:tid 29103] [client 34.73.31.183:33648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mwrn.microscopedia.com"] [uri "/.git/config"] [unique_id "aigxNKF7LYFF4kuwjwdkawAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:57:10
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:57:06.060609 2026] [security2:error] [pid 4530:tid 4530] [client 34.73.31.183:37824] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "podcasts.freedrm.org"] [uri "/.git/config"] [unique_id "aigNot6LsKo6n7MxcMah7QAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:14:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:14:31.200742 2026] [security2:error] [pid 25419:tid 25419] [client 34.73.31.183:37916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boraimpact.com"] [uri "/.git/config"] [unique_id "aigDp-7_JzwFbrRMMsUHBwAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:18:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:18:19.251643 2026] [security2:error] [pid 12717:tid 12717] [client 34.73.31.183:59318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bestprostate.com"] [uri "/.git/config"] [unique_id "aif2ezvI8Ymo-EcgWh-MLQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:24:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:24:31.393926 2026] [security2:error] [pid 15435:tid 15435] [client 34.73.31.183:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ccamp.dev"] [uri "/.git/config"] [unique_id "aifp34h-YC9Qqak1-lVkGQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-06-09 02:04:58
(3 days ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.73.31.183 108.162.237.153 - - [08/Jun/2026:23:04 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 34.73.31.183 108.162.237.153 - - [08/Jun/2026:23:04:49 -0300] "GET /.git/config HTTP/1.1" 404 18193
show less
Bad Web Bot
๐ซ๐ฎ
as211431.net
2026-06-09 01:18:31
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.9 Safari/536.5
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 00:42:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.31.183 (183.31.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:42:04.058691 2026] [security2:error] [pid 8888:tid 8888] [client 34.73.31.183:41704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "designamb.com"] [uri "/.git/config"] [unique_id "aidhXDtJP0G8hRgZZZEzMwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-06-09 00:42:00
(3 days ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
๐ฉ๐ช
4server
2026-06-08 18:44:34
(4 days ago)
[MonJun0820:44:32.2637892026][security2:error][pid1667721:tid1667787][client34.73.31.183:0]ModSecuri ...
show more
[MonJun0820:44:32.2637892026][security2:error][pid1667721:tid1667787][client34.73.31.183:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autodiscover.atelier-lara.ch\"][uri\"/.git/config\"][unique_id\"aicNkNybaDe2aedSsfp9rgAAAIU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
Lino Project
2026-06-08 18:15:46
(4 days ago)
34.73.31.183 - - [08/Jun/2026:20:15:42 +0200] "GET /.git/config HTTP/1.1" 403 3806 "-" "grub-client- ...
show more
34.73.31.183 - - [08/Jun/2026:20:15:42 +0200] "GET /.git/config HTTP/1.1" 403 3806 "-" "grub-client-1.5.3; (grub-client-1.5.3; Crawl your own stuff with http://grub.org)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack