๐บ๐ธ
TPI-Abuse
2026-08-29 06:32:06
(27 seconds ago)
(mod_security) mod_security (id:210492) triggered by 8.231.166.98 (98.166.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.166.98 (98.166.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:31:58.774898 2026] [security2:error] [pid 8213:tid 8213] [client 8.231.166.98:40150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sandiego99.smogsandiego.com"] [uri "/public/.git/config"] [unique_id "apJ83nHp0DxxNB_cCDP3bAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
webadmin
2026-08-29 01:59:42
(4 hours ago)
8.231.166.98 - - [29/Aug/2026:03:59:41 +0200] "GET /var/www/.git/config HTTP/1.1" 400 25 "-" "crusad ...
show more
8.231.166.98 - - [29/Aug/2026:03:59:41 +0200] "GET /var/www/.git/config HTTP/1.1" 400 25 "-" "crusader-worker/1.0" (de.inweo.eu / 195.116.29.46)
8.231.166.98 - - [29/Aug/2026:03:59:41 +0200] "GET /.git/config HTTP/1.1" 400 25 "-" "crusader-worker/1.0" (de.inweo.eu / 195.116.29.46)
8.231.166.98 - - [29/Aug/2026:03:59:41 +0200] "GET /app/.git/config HTTP/1.1" 400 25 "-" "crusader-worker/1.0" (de.inweo.eu / 195.116.29.46)
8.231.166.98 - - [29/Aug/2026:03:59:41 +0200] "GET /htdocs/.git/config HTTP/1.1" 400 25 "-" "crusader-worker/1.0" (de.inweo.eu / 195.116.29.46)
8.231.166.98 - - [29/Aug/2026:03:59:41 +0200] "GET /wordpress/.git/config HTTP/1.1" 400 25 "-" "crusader-worker/1.0" (de.inweo.eu / 195.116.29.46)
show less
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-08-29 00:59:12
(5 hours ago)
Probing for non-installed web apps or current vulnerabilities.
Hacking
Web App Attack
๐ฉ๐ช
Philister11
2026-08-29 00:00:34
(6 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files (US/AS396982)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 23:49:23
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.166.98 (98.166.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.166.98 (98.166.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:49:16.636997 2026] [security2:error] [pid 5807:tid 5807] [client 8.231.166.98:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dentguyvt.com"] [uri "/var/www/.git/config"] [unique_id "apIefA8lCwiiykyY2aB2CQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-08-28 23:01:25
(7 hours ago)
[29/Aug/2026:01:01:25 +0200] 178795808560.786851 8.231.166.98 56112 217.154.7.177 443
[29/Aug/2026:0 ...
show more
[29/Aug/2026:01:01:25 +0200] 178795808560.786851 8.231.166.98 56112 217.154.7.177 443
[29/Aug/2026:01:01:25 +0200] 178795808542.632497 8.231.166.98 56126 217.154.7.177 443
[29/Aug/2026:01:01:25 +0200] 178795808511.513545 8.231.166.98 56156 217.154.7.177 443
[29/Aug/2026:01:01:25 +0200] 178795808535.685485 8.231.166.98 56106 217.154.7.177 443
[29/Aug/2026:01:01:25 +0200] 178795808535.257764 8.231.166.98 56152 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฌ๐ง
pinguin
2026-08-28 21:17:21
(9 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /backend/.git/config
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-08-28 19:00:02
(11 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:08:25
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.166.98 (98.166.231.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.166.98 (98.166.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:08:19.367455 2026] [security2:error] [pid 13511:tid 13511] [client 8.231.166.98:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.caspina.com"] [uri "/app/.git/config"] [unique_id "apHOk5IY3M5poF3X1lV1ewAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 16:48:10
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-08-28 13:24:09
(17 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
4server
2026-08-28 13:03:38
(17 hours ago)
[FriAug2815:03:34.3385042026][security2:error][pid2685149:tid2685243][client8.231.166.98:0]ModSecuri ...
show more
[FriAug2815:03:34.3385042026][security2:error][pid2685149:tid2685243][client8.231.166.98:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"serban.ch.136-243-54-122.cpanel.site\"][uri\"/site/.git/config\"][unique_id\"apGHJtefFSjegeGkBeSnhQAAAM4\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 12:26:09
(18 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-28 12:14:19
(18 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 11:43:44
(18 hours ago)
Web attack/malicious scanning detected
Web App Attack