๐ฌ๐ง
Oakley
2026-06-09 07:31:40
(48 minutes ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐ฌ๐ง
pinguin
2026-06-09 06:11:14
(2 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Linux U; en-US) AppleWebKit/528.5 (KHTML, like Gecko, Safari/528.5 ) Version/4.0 Kindle/3.0 (screen 600x800; rotate)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ฐ
ScamAware
2026-06-09 04:52:48
(3 hours ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 04:51:51
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:51:47.676766 2026] [security2:error] [pid 26008:tid 26010] [client 35.236.254.178:38972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keetons.net"] [uri "/.git/config"] [unique_id "aieb43qILviD51uzcP3tpwAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 04:31:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:31:14.269464 2026] [security2:error] [pid 17861:tid 17861] [client 35.236.254.178:38124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.meridianranchdrc.org"] [uri "/.git/config"] [unique_id "aieXErjtPZOf5q4T6c0DLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-09 04:25:05
(3 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.236.254.178 (US/United States/178. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.236.254.178 (US/United States/178.254.236.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ฉ๐ช
Progetto1
2026-06-09 04:01:01
(4 hours ago)
Detected via HAProxyScanner at 2026-06-09 04:01:01 UTC on destination port WEB (80/443). Repeated sc ...
show more
Detected via HAProxyScanner at 2026-06-09 04:01:01 UTC on destination port WEB (80/443). Repeated scan / connection.
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 01:38:12
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 21:38:08.866636 2026] [security2:error] [pid 15588:tid 15588] [client 35.236.254.178:34190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doctorspainmanagement.com"] [uri "/.git/config"] [unique_id "aidugCcbY0m_Yap7drZqUgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-06-09 01:22:04
(6 hours ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 01:05:42
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 21:05:36.116055 2026] [security2:error] [pid 29589:tid 29589] [client 35.236.254.178:36594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "premiumenterprisessolution.com"] [uri "/.git/config"] [unique_id "aidm4ELUzDixJ64avpHcYgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:09:08
(10 hours ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking
Anonymous
2026-06-08 19:00:03
(13 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 18:59:27
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 14:59:21.934413 2026] [security2:error] [pid 7728:tid 7728] [client 35.236.254.178:50080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "concertosupport.com"] [uri "/.git/config"] [unique_id "aicRCVqVRzH-ZStk2NVj3gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 17:03:27
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.254.178 (178.254.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 13:03:19.807427 2026] [security2:error] [pid 1158:tid 1158] [client 35.236.254.178:40132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidnevue.com"] [uri "/.git/config"] [unique_id "aib110xx6X3rsCnUlBBkBgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-06-08 16:07:01
(16 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack