π«π·
mrcrassi
2026-08-28 09:20:15
(16 hours ago)
Triggered Cloudflare WAF (bic) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint ...
show more
Triggered Cloudflare WAF (bic) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/HEAD
UA: Python-urllib/3.10
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΏπ¦
conure.sh
2026-08-28 09:17:17
(16 hours ago)
csagent: score 20.5: 404 noise floor x2, secrets grab x2; 2 domain(s) in 0s
Web App Attack
π³π΄
jad-abuse
2026-08-27 02:46:57
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 00:14:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 20:14:31.368134 2026] [security2:error] [pid 2096:tid 2096] [client 45.130.203.219:65067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frightlibrary.org"] [uri "/.git/HEAD"] [unique_id "ao-BZ_UB6Rg2yEY8eixAHwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 23:16:19
(2 days ago)
apache vulnerability scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 20:46:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 16:46:00.380404 2026] [security2:error] [pid 32215:tid 32215] [client 45.130.203.219:58813] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fgrotary.org"] [uri "/.git/HEAD"] [unique_id "ao9QiOAxbOMA83p767QTawAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 20:44:24
(2 days ago)
45.130.203.219 - - [27/Aug/2026:04:44:24 +0800] "GET /.git/HEAD HTTP/1.1" 301 246 "-" "Python-urllib ...
show more
45.130.203.219 - - [27/Aug/2026:04:44:24 +0800] "GET /.git/HEAD HTTP/1.1" 301 246 "-" "Python-urllib/3.10"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 16:11:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:10:56.149377 2026] [security2:error] [pid 2044:tid 2044] [client 45.130.203.219:28611] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-germany.com.yacht-register-holland.com"] [uri "/.git/HEAD"] [unique_id "ao8QEFxi-mS5APyykvfjcgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 23:07:14
(4 days ago)
Automated web scanner. Requested suspicious paths: /.git/HEAD. UTC: 2026-08-24 22:50:26.
Web App Attack
π¬π§
AvonleaConsulting
2026-08-24 22:58:30
(4 days ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
π¬π§
AvonleaConsulting
2026-08-24 20:08:46
(4 days ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 15:52:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 11:52:11.988594 2026] [security2:error] [pid 31950:tid 31973] [client 45.130.203.219:58005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "metastrata.com"] [uri "/.git/HEAD"] [unique_id "aoxoqoYiWN6O6KmK9NXtWgAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 13:48:45
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:48:38.470169 2026] [security2:error] [pid 25003:tid 25003] [client 45.130.203.219:21703] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fxbgsanta.com"] [uri "/.git/HEAD"] [unique_id "aoxLtl8NrM2aK5gb2cDNCgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
vtchost.com
2026-08-24 11:25:38
(4 days ago)
vtchost.com:80 45.130.203.219 - - [24/Aug/2026:13:25:36 +0200] "GET /.git/HEAD HTTP/1.1" 418 231 "-" ...
show more
vtchost.com:80 45.130.203.219 - - [24/Aug/2026:13:25:36 +0200] "GET /.git/HEAD HTTP/1.1" 418 231 "-" "Python-urllib/3.10"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 11:22:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:22:11.748320 2026] [security2:error] [pid 3842:tid 3842] [client 45.130.203.219:41301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nhhostas.com"] [uri "/.git/HEAD"] [unique_id "aowpYxsbWVu_hb00A0Y4EgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack