๐ฌ๐ง
thetomtaylor.co.uk
2026-07-21 21:09:02
(5 hours ago)
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [mx01,mx03,wa01,wa02]
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-07-21 20:25:46
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-21 20:19:16
(6 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.201.227.47 (TW/Taiwan/47.227.201 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.201.227.47 (TW/Taiwan/47.227.201.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฆ๐น
Renรฉ Hickersberger
2026-07-21 20:06:09
(6 hours ago)
malicious bot detected: violations="hit-honeypot"; user_agent=""
Web App Attack
๐ซ๐ท
dynamix
2026-07-21 19:58:35
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 19:56:32
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.227.47 (47.227.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.227.47 (47.227.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 15:56:24.452653 2026] [security2:error] [pid 1146:tid 1146] [client 35.201.227.47:55630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.grace.michaelward.com"] [uri "/.git/config"] [unique_id "al_O6O-OmlGo2vtCPd9NBQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-07-21 19:54:56
(6 hours ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ญ๐ณ
soporte
2026-07-21 19:49:22
(6 hours ago)
Probe for vulnerabilities. Path attempted: /.git/config
Web App Attack
๐ช๐ธ
pipeline.es
2026-07-21 19:46:19
(6 hours ago)
Port scanning / recon | Evidence: date=2026-07-21 time=21:42:53 devname="[redacted]" devid="[redacte ...
show more
Port scanning / recon | Evidence: date=2026-07-21 time=21:42:53 devname="[redacted]" devid="[redacted]" eventtime=1784662973447913900 tz=\"+0200\" logid=\"0000000013\" type=\"traffic\" subtype=\"forward\" level=\"notice\" vd="[redacted]" srcip=35.201.227.47 srcport=54496 srcintf="[redacted]" srcintfrole=\"wan\" dstip=[redacted] dstport=443 dstintf="[redacted]" dstintfrole=\"lan\" srccountry=\"Taiwan\" dstcountry=\"Spain\" sessioni | ASN: GOOGLE-CLOUD-PLATFORM | Country: TW
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 19:38:59
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.227.47 (47.227.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.227.47 (47.227.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 15:38:52.226331 2026] [security2:error] [pid 13681:tid 13681] [client 35.201.227.47:60380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medusakenya.com"] [uri "/.git/config"] [unique_id "al_KzH5gFhP9652xzG2HzQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-07-21 19:09:58
(7 hours ago)
Triggered Cloudflare WAF (firewallManaged) from TW.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from TW.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
mail.avx.gr
2026-07-21 18:59:27
(7 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.201.227.47 - - [21/Jul/2026:21:59:26 +0300] "G ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.201.227.47 - - [21/Jul/2026:21:59:26 +0300] "GET /.git/config HTTP/1.1" 404 146 "-" "-"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 18:58:12
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.227.47 (47.227.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.227.47 (47.227.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:58:08.703964 2026] [security2:error] [pid 22654:tid 22654] [client 35.201.227.47:40724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lastreetsbykarensperling.com"] [uri "/.git/config"] [unique_id "al_BQOmrQKZ-Gx33OesJTAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-21 18:45:25
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-07-21 18:41:27
(7 hours ago)
trolling for resource vulnerabilities
Web App Attack