๐บ๐ธ
TPI-Abuse
2026-08-29 08:59:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:59:50.101623 2026] [security2:error] [pid 22986:tid 22986] [client 136.107.102.165:57698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "97films.media"] [uri "/html/.git/config"] [unique_id "apKfhr3wVamUAaesdZuWqgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-29 02:10:03
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ธ๐ช
EmK530
2026-08-28 22:43:49
(3 days ago)
URL flagged by RegEx: /app/.git/config
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 22:04:21
(3 days ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 21:49:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:49:46.480508 2026] [security2:error] [pid 19842:tid 19842] [client 136.107.102.165:59548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.paintingqueen.benshermanguitar.com"] [uri "/html/.git/config"] [unique_id "apICevDRw9_KfgI9ItsYmgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 20:54:49
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 18:08:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:08:19.165454 2026] [security2:error] [pid 13489:tid 13489] [client 136.107.102.165:57642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.intergalactichuman.com.mroxygen.org"] [uri "/www/.git/config"] [unique_id "apHOkzqHD9HBlMIiqYD6PgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
infra-monitor
2026-08-28 18:00:07
(3 days ago)
Automated ban via infra-monitor: suspicious-probe, mgmt-path-probe, crowdsecurity/http-probing, +1 m ...
show more
Automated ban via infra-monitor: suspicious-probe, mgmt-path-probe, crowdsecurity/http-probing, +1 more
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:26:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:26:30.001767 2026] [security2:error] [pid 27901:tid 27901] [client 136.107.102.165:37928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redtraffic.media"] [uri "/wordpress/.git/config"] [unique_id "apGopgSscEdXfIoM7q3FdQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 15:09:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:09:05.885360 2026] [security2:error] [pid 28811:tid 28811] [client 136.107.102.165:43436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lavozdominicana.com"] [uri "/.git/config"] [unique_id "apGkkRtJCKf9EYzqMognzgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 13:19:46
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ญ๐บ
DumaNet
2026-08-28 04:34:00
(3 days ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 16:39:53
Source IP: 136.10 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 16:39:53
Source IP: 136.107.102.165
Portion of the log(s):
136.107.102.165 - [27/Aug/2026:16:39:53 +0200] "GET /api/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.102.165 - [27/Aug/2026:16:39:53 +0200] "GET /backend/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.102.165 - [27/Aug/2026:16:39:53 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.102.165 - [27/Aug/2026:16:39:53 +0200] "GET /site/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.102.165 - [27/Aug/2026:16:39:53 +0200] "GET /var/www/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.102.165 - [27/Aug/2026:16:39:53 +0200] "GET /public/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.102.165 - [27/Aug/2026:16:39:53 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.102.165 - [27/Aug/2026:16:39:53 +0200] "GET /html/.git/
show less
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 00:06:18
(3 days ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐ฉ๐ช
MBombeck
2026-08-27 20:21:01
(4 days ago)
Fail2Ban/traefik-botsearch on ops-01.bombeck.io: banned after 5 failures
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:19:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.102.165 (165.102.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:19:38.051380 2026] [security2:error] [pid 15648:tid 15648] [client 136.107.102.165:59554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lumberwizard.com.wizind.com"] [uri "/public/.git/config"] [unique_id "apBjmso7dUj0vAd3G4rUZgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack