π¦πΊ
paulshipley.com.au
2026-08-31 19:06:09
(11 hours ago)
[Tue Sep 01 05:06:07.975353 2026] [security2:error] [pid 148113] [client 45.130.203.168:59757] [clie ...
show more
[Tue Sep 01 05:06:07.975353 2026] [security2:error] [pid 148113] [client 45.130.203.168:59757] [client 45.130.203.168] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "underconstruction.paulshipley.info"] [uri "/.git/HEAD"] [unique_id "apXQn-uWzg4TUi5auYEgxgAAABQ"]
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 21:43:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 17:43:23.302247 2026] [security2:error] [pid 28180:tid 28180] [client 45.130.203.168:56471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.babylontravelone.com"] [uri "/.git/HEAD"] [unique_id "apSj-zQx9t4xmj44M1HvFgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 11:16:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 07:16:36.894658 2026] [security2:error] [pid 2112:tid 2112] [client 45.130.203.168:24203] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.juniperhills.davidwoodard.com"] [uri "/.git/HEAD"] [unique_id "apQRFBERhXwkxIW0pQXEvAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-08-30 10:14:12
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
Anonymous
2026-08-30 03:43:33
(2 days ago)
apache vulnerability scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 03:38:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 23:38:12.526105 2026] [security2:error] [pid 1897865:tid 1897913] [client 45.130.203.168:28303] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.linfoulk.org"] [uri "/.git/HEAD"] [unique_id "apOlpFhegP2sDqbb5vUzHAAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
vtchost.com
2026-08-29 11:07:42
(2 days ago)
minux.cc:443 45.130.203.168 - - [29/Aug/2026:13:07:41 +0200] "GET /404.html HTTP/1.1" 200 4765 "-" " ...
show more
minux.cc:443 45.130.203.168 - - [29/Aug/2026:13:07:41 +0200] "GET /404.html HTTP/1.1" 200 4765 "-" "Mozilla/5.0"
...
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-29 09:05:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:05:08.626808 2026] [security2:error] [pid 21128:tid 21128] [client 45.130.203.168:48959] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gdg1.bizecomm.com"] [uri "/.git/HEAD"] [unique_id "apKgxFQqxqlvn1iQ8Ynl9gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
dyln
2026-08-29 07:59:25
(2 days ago)
Dyls honeypot brute-force: proto8 (1 total hits)
Brute-Force
π«π·
mrcrassi
2026-08-26 23:07:57
(5 days ago)
Triggered Cloudflare WAF (bic) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint ...
show more
Triggered Cloudflare WAF (bic) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/HEAD
UA: Python-urllib/3.10
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-26 19:34:54
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:34:49.278081 2026] [security2:error] [pid 21016:tid 21016] [client 45.130.203.168:41071] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "muslera.com"] [uri "/.git/HEAD"] [unique_id "ao8_2UxON8wAeiHfnCBKRQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 17:44:29
(5 days ago)
fail2ban: Sensitive web probes detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 16:11:02
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:10:56.149378 2026] [security2:error] [pid 2046:tid 2046] [client 45.130.203.168:31675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-slovenia.com.yacht-register-holland.com"] [uri "/.git/HEAD"] [unique_id "ao8QEIDtxGTQSyLcEvv2OgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 22:02:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 18:02:29.612228 2026] [security2:error] [pid 8803:tid 8803] [client 45.130.203.168:26309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theebees.com"] [uri "/.git/HEAD"] [unique_id "aoy_dQZFLP6DX_TmzIng1wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
jkhorvath.com
2026-08-24 20:24:01
(1 week ago)
Request for URL /files/
Phishing
Brute-Force
Web App Attack