๐ฆ๐บ
2000cn.com.au
2026-08-23 15:08:58
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฌ๐ง
kie
2026-08-23 15:00:53
(8 hours ago)
23-08-2026:14:59:44UTC [Nginx Web Server] Suspicious web request: path:/.git (2 request(s)).
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-08-23 03:12:19
(20 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 85.237.212.152 162.158.102.53 - - [21/Aug/2026:10:37:09 - ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 85.237.212.152 162.158.102.53 - - [21/Aug/2026:10:37:09 -0300] "GET /.git/config HTTP/1.1" 404 414
85.237.212.152 172.64.200.31 - - [21/Aug/2026:10:37:10 -0300] "GET /.git/config HTTP/1.1" 404 414
show less
Bad Web Bot
๐ง๐ช
cmbplf
2026-08-22 11:32:04
(1 day ago)
420 requests with url.path */.git/config
401 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-22 11:12:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 85.237.212.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.237.212.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 07:12:32.387726 2026] [security2:error] [pid 31451:tid 31503] [client 85.237.212.152:50757] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adultbaja.com"] [uri "/.git/config"] [unique_id "aomEIPJR4DrIX7ajLU8sLQAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 10:22:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 85.237.212.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.237.212.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:21:59.395390 2026] [security2:error] [pid 25438:tid 25438] [client 85.237.212.152:58317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "n3fjp.com"] [uri "/.git/config"] [unique_id "aol4R4nXxSDLGjHOCFftAAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-22 10:11:22
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-22 10:07:52
(1 day ago)
[22/Aug/2026:13:07:52 +0300] -- 85.237.212.152 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 10:03:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 85.237.212.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.237.212.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:03:47.387574 2026] [security2:error] [pid 6385:tid 6385] [client 85.237.212.152:38165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wryemusings.com"] [uri "/.git/config"] [unique_id "aol0A-UTNEcMmBlf3nmeCwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jcbriar
2026-08-22 09:41:07
(1 day ago)
Searching for vulnerable scripts
Hacking
Web App Attack
Anonymous
2026-08-22 07:38:18
(1 day ago)
GET /.git/config HTTP/1.1
...
Web App Attack
๐ง๐ช
voormedia
2026-08-22 05:24:24
(1 day ago)
Accessed trap at '/.git/config'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 05:14:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 85.237.212.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.237.212.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 01:14:25.800632 2026] [security2:error] [pid 28173:tid 28173] [client 85.237.212.152:58319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.creartest.com"] [uri "/.git/config"] [unique_id "aokwMdt5MrQkw9_-NZ7JDgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 04:28:04
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2026-08-22 04:17:22
(1 day ago)
Suspicious malicious activity
Hacking