๐ณ๐ฑ
homeshowdomain.nl
2026-08-31 22:02:57
(5 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-30.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-31 09:33:45
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:33:41.224132 2026] [security2:error] [pid 20339:tid 20339] [client 89.249.86.28:35102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wakims.com"] [uri "/.git/config"] [unique_id "apVKdduxQ3a0kOizzkCI0gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-31 08:51:30
(18 hours ago)
Triggered Cloudflare WAF (firewallCustom) from LT.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from LT.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-31 08:39:11
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:39:04.491034 2026] [security2:error] [pid 3281:tid 3281] [client 89.249.86.28:55332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bacona.org"] [uri "/.git/config"] [unique_id "apU9qPPP-sATsIixYro8lgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 08:23:18
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:23:12.476442 2026] [security2:error] [pid 3720759:tid 3720853] [client 89.249.86.28:42458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.antidote-it.com"] [uri "/.git/config"] [unique_id "apU58Ei-3ujBU-IfRDiu_AAAAgU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 06:51:00
(20 hours ago)
Brute-Force
๐ญ๐บ
miszterx.hu
2026-08-31 06:42:15
(20 hours ago)
XORP (haproxy): 2x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 2x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-31 05:48:14
(21 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 04:28:58
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 00:28:53.526582 2026] [security2:error] [pid 16477:tid 16477] [client 89.249.86.28:47568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tedharris.com"] [uri "/.git/config"] [unique_id "apUDBVB02Iz-Lle9RQmDnAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 03:33:04
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 23:32:56.782131 2026] [security2:error] [pid 7227:tid 7227] [client 89.249.86.28:37062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.emisoni.com"] [uri "/.git/config"] [unique_id "apT16Dxo_SEHj8AkUgisrQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Jochen Pretli
2026-08-31 02:49:31
(1 day ago)
connection to honeypot
Email Spam
Port Scan
๐ซ๐ท
Baking333
2026-08-31 02:42:16
(1 day ago)
[redacted] 89.249.86.28 - - [31/Aug/2026:03:42:14 +0100] "GET /.git/config HTTP/1.1" 302 6758 0/6917 ...
show more
[redacted] 89.249.86.28 - - [31/Aug/2026:03:42:14 +0100] "GET /.git/config HTTP/1.1" 302 6758 0/69176 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" [redacted] 89.249.86.28 - - [31/Aug/2026:03:42:14 +0100] "GET / HTTP/1.1" 200 13795 0/121722 "https://[redacted]/.git/config" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 02:34:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 89.249.86.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 22:33:58.111173 2026] [security2:error] [pid 13741:tid 13741] [client 89.249.86.28:51840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jsdavison.com"] [uri "/.git/config"] [unique_id "apToFhyI3ov1ix9wC3ZvqQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
etu brutus
2026-08-31 02:27:41
(1 day ago)
89.249.86.28 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
Anonymous
2026-08-31 02:09:20
(1 day ago)
Web application attack detected.
Web App Attack