๐ญ๐ฐ
ncsr-sec
2026-08-21 18:37:06
(1 day ago)
Attacked NCSR.CN production server: SSH brute-force / web scanning / honeypot trips. fail2ban banned ...
show more
Attacked NCSR.CN production server: SSH brute-force / web scanning / honeypot trips. fail2ban banned. Evidence in server logs.
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
MyGlobalFlowers
2026-08-21 17:39:09
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 17:36:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.253.122.218 (218.122.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.122.218 (218.122.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 13:36:41.098150 2026] [security2:error] [pid 11811:tid 11820] [client 35.253.122.218:42232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.debeneesse.com"] [uri "/.git/config"] [unique_id "aoiMqaRCQdVi--y3Rj1s4gAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-08-21 17:35:16
(1 day ago)
-:443 35.253.122.218 - - [21/Aug/2026:19:35:15 +0200] - "GET /.git/config HTTP/1.1" 403 6335 "-" "-"
Bad Web Bot
Anonymous
2026-08-21 17:34:24
(1 day ago)
35.253.122.218 - - [21/Aug/2026:17:34:24 +0000] "GET /.git/config HTTP/2.0" 403 146 "-" "-" "35.253 ...
show more
35.253.122.218 - - [21/Aug/2026:17:34:24 +0000] "GET /.git/config HTTP/2.0" 403 146 "-" "-" "35.253.122.218" "-"
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-08-21 17:31:39
(1 day ago)
251 requests with url.path *.git/*
240 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-21 17:21:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.253.122.218 (218.122.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.122.218 (218.122.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 13:21:00.069902 2026] [security2:error] [pid 31133:tid 31133] [client 35.253.122.218:55510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hockey312.com"] [uri "/.git/config"] [unique_id "aoiI_LmgB5ZHJwWbiPuJkwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
myip.foo
2026-08-21 17:02:24
(1 day ago)
[myip.foo] 35.253.122.218 - - [21/Aug/2026:17:02:24 +0000] "GET /.git/config HTTP/1.1" 404 150 "-" " ...
show more
[myip.foo] 35.253.122.218 - - [21/Aug/2026:17:02:24 +0000] "GET /.git/config HTTP/1.1" 404 150 "-" "-"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 17:01:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.253.122.218 (218.122.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.122.218 (218.122.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 13:01:11.465888 2026] [security2:error] [pid 1639:tid 1639] [client 35.253.122.218:60732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thegyde.com"] [uri "/.git/config"] [unique_id "aoiEV3gZVnsOQptHlp3mcQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-21 16:52:47
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 16:43:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.253.122.218 (218.122.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.122.218 (218.122.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 12:43:49.896807 2026] [security2:error] [pid 11332:tid 11354] [client 35.253.122.218:60194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eatdrinkgroove.com"] [uri "/.git/config"] [unique_id "aoiARdvfNDldy5J2IgXSTwAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-08-21 16:33:24
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-08-21 16:31:07
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 16:21:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.253.122.218 (218.122.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.122.218 (218.122.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 12:21:28.814332 2026] [security2:error] [pid 3736:tid 3736] [client 35.253.122.218:41712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "computerdoc-rx.com"] [uri "/.git/config"] [unique_id "aoh7CPZC8Ybys4n6oEHHZwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
000rosiu
2026-08-21 16:17:10
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/config | UA: Empty string โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot