๐บ๐ธ
TPI-Abuse
2026-10-05 01:31:55
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.172.177 (177.172.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.172.177 (177.172.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 21:31:49.837304 2026] [security2:error] [pid 12584:tid 12584] [client 34.97.172.177:52700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisdomsco.com"] [uri "/.git/config"] [unique_id "asL-BclQhDZ933W2AsSgcwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
1gz
2026-10-04 23:31:45
(12 hours ago)
Triggered Cloudflare WAF (firewallManaged) from JP.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from JP.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ญ
zynex
2026-10-04 22:48:39
(12 hours ago)
URL Probing: /server/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 22:00:29
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.172.177 (177.172.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.172.177 (177.172.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 18:00:22.563768 2026] [security2:error] [pid 660:tid 660] [client 34.97.172.177:42148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wiro.am"] [uri "/.git/config"] [unique_id "asLMdnCo7JMdA_USHg3yqAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-04 21:41:01
(13 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-04 21:22:27
(14 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
netman
2026-10-04 20:47:43
(14 hours ago)
HTTP: 34.97.172.177 blocked because of 100 failures
...
DDoS Attack
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-04 20:39:45
(14 hours ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
middelkoopcc
2026-10-04 19:45:00
(15 hours ago)
2026-10-04 21:43:20 GET /.git/config [301] && 2026-10-04 21:43:21 GET /.env [301] && 2026-10-04 21:4 ...
show more
2026-10-04 21:43:20 GET /.git/config [301] && 2026-10-04 21:43:21 GET /.env [301] && 2026-10-04 21:43:23 GET /.env.bak [301] && 120 more within 20 minutes
show less
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-10-04 18:16:46
(17 hours ago)
Cross-vhost secrets/RCE probing campaign
Web App Attack
Hacking
๐ณ๐ด
jad-abuse
2026-10-04 17:55:04
(17 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup. Observed by 1 sensor(s); 617 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 12:24:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.97.172.177 (177.172.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.172.177 (177.172.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 08:24:49.034457 2026] [security2:error] [pid 14040:tid 14040] [client 34.97.172.177:35038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amychop.homehealth101.com"] [uri "/.git/config"] [unique_id "arEiEeSsIlddHKQ6y7E9IgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-21 12:01:00
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 11:17:21
(2 weeks ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐ฉ๐ช
LRob
2026-09-21 10:39:18
(2 weeks ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-21 10:39 UTC
show less
Hacking
Web App Attack