๐ซ๐ท
masterguru
2026-09-24 08:32:02
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 08:18:30
(2 days ago)
[ti-tinov] Web exploit scanning: 3 suspicious requests detected by fail2ban jail <name>. Example: 8. ...
show more
[ti-tinov] Web exploit scanning: 3 suspicious requests detected by fail2ban jail <name>. Example: 8.230.21.17 - - \[24/Sep/2026:10:18:26 +0200\] "GET /html/.git/config HTTP/1.1" 301 5900 "-" "crusader-worker/1.0"
8.230.21.17 - - \[24/Sep/2026:10:18:26 +0200\] "GET /backend/.git/config HTTP/1.1" 301 5900 "-" "crusader-worker/1.0"
8.230.21.17 - - \[24/Sep/2026:10:18:26 +0200\] "GET /wordpress/.git/config HTTP/1.1" 301 5900 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-24 08:03:44
(2 days ago)
Web App Attack
๐ซ๐ท
dwmp
2026-09-24 05:35:24
(2 days ago)
[24/Sep/2026:07:35:23.511381 +0200] arS2mzse4dFWAqckFWaxbwAAAEM 8.230.21.17 34660 38.242.227.117 708 ...
show more
[24/Sep/2026:07:35:23.511381 +0200] arS2mzse4dFWAqckFWaxbwAAAEM 8.230.21.17 34660 38.242.227.117 7081
[24/Sep/2026:07:35:23.524237 +0200] arS2mzse4dFWAqckFWaxcQAAAEc 8.230.21.17 34624 38.242.227.117 7081
[24/Sep/2026:07:35:23.525679 +0200] arS2mzse4dFWAqckFWaxcAAAAFY 8.230.21.17 34710 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-24 03:10:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:10:30.735128 2026] [security2:error] [pid 11320:tid 11332] [client 8.230.21.17:48476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.colinkyffinmusic.com"] [uri "/src/.git/config"] [unique_id "arSUpv1ds3dQqIfJIqkEGQAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:49:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:49:22.501324 2026] [security2:error] [pid 21350:tid 21350] [client 8.230.21.17:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cloudex.click"] [uri "/www/.git/config"] [unique_id "arSBorcsbhiibnzXWHqBOwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 01:43:24
(3 days ago)
540 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 00:37:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:37:44.089305 2026] [security2:error] [pid 7407:tid 7407] [client 8.230.21.17:42954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.itimetable21.com"] [uri "/site/.git/config"] [unique_id "arRw2LzFRO7pFywAPHRhuAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 23:54:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 19:54:27.250565 2026] [security2:error] [pid 4833:tid 4833] [client 8.230.21.17:46406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cozydesignae.com"] [uri "/public/.git/config"] [unique_id "arRms3JyR90AFHS8bIOEQQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-23 23:47:44
(3 days ago)
8.230.21.17 - - [24/Sep/2026:01:47:41 +0200] "GET /.git/config HTTP/1.1" 403 4547 "-" "crusader-work ...
show more
8.230.21.17 - - [24/Sep/2026:01:47:41 +0200] "GET /.git/config HTTP/1.1" 403 4547 "-" "crusader-worker/1.0"
8.230.21.17 - - [24/Sep/2026:01:47:41 +0200] "GET /public/.git/config HTTP/1.1" 404 4543 "-" "crusader-worker/1.0"
8.230.21.17 - - [24/Sep/2026:01:47:41 +0200] "GET /api/.git/config HTTP/1.1" 404 4542 "-" "crusader-worker/1.0"
8.230.21.17 - - [24/Sep/2026:01:47:41 +0200] "GET /html/.git/config HTTP/1.1" 404 4543 "-" "crusader-worker/1.0"
8.230.21.17 - - [24/Sep/2026:01:47:41 +0200] "GET /var/www/.git/config HTTP/1.1" 404 4542 "-" "crusader-worker/1.0"
8.230.21.17 - - [24/Sep/2026:01:47:41 +0200] "GET /www/.git/config HTTP/1.1" 404 4542 "-" "crusader-worker/1.0"
8.230.21.17 - - [24/Sep/2026:01:47:41 +0200] "GET /app/.git/config HTTP/1.1" 404 4544 "-" "crusader-worker/1.0"
8.230.21.17 - - [24/Sep/2026:01:47:41 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 4544 "-" "crusader-worker/1.0"
8.230.21.17 - - [24/Sep/2026:01:47:41 +0200] "GET /backend/.git/config HTTP/1.1" 404 4542 "-"
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 20:36:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:36:09.177859 2026] [security2:error] [pid 19404:tid 19404] [client 8.230.21.17:58912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clarktec.com"] [uri "/backend/.git/config"] [unique_id "arQ4OTH2blPZwBKMqurPAwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:08:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.21.17 (17.21.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:08:39.467679 2026] [security2:error] [pid 7153:tid 7153] [client 8.230.21.17:53782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brtc.us.joshuashands.org"] [uri "/backend/.git/config"] [unique_id "arPrd81lV23ASTJdGi1irQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 10:54:04
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
Little Iguana
2026-09-23 10:19:13
(3 days ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐จ๐ญ
ca
2026-09-23 05:52:46
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking