Anonymous
2026-09-04 21:30:51
(34 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
AetherFox
2026-09-04 20:03:55
(2 hours ago)
AetherFox VoidGuard detected: [Fri Sep 04 20:03:54.300881 2026] [authz_core:error] [pid 667510:tid 6 ...
show more
AetherFox VoidGuard detected: [Fri Sep 04 20:03:54.300881 2026] [authz_core:error] [pid 667510:tid 667519] [client 136.107.221.171:50526] AH01630: client denied by server configuration: proxy:http://[MASKED]/app/.git/config
[Fri Sep 04 20:03:54.300989 2026] [authz_core:error] [pid 667510:tid 667519] [client 136.107.221.171:50526] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Fri Sep 04 20:03:54.301239 2026] [authz_core:error] [pid 667510:tid 667538] [client 136.107.221.171:50528] AH01630: client denied by server configuration: proxy:http://[MASKED]/www/.git/config
[Fri Sep 04 20:03:54.301331 2026] [authz_core:error] [pid 667510:tid 667535] [client 136.107.221.171:50508] AH01630: client denied by server configuration: proxy:http://[MASKED]/html/.git/config
[Fri Sep 04 20:03:54.301339 2026] [authz_core:error] [pid 667510:tid 667538] [client 136.107.221.171:50528] AH01630: client denied by server configuration: /var/www/htm
...
show less
Bad Web Bot
Web App Attack
🇩🇪
Stefan Dreher
2026-09-04 19:07:13
(2 hours ago)
136.107.221.171 - - [04/Sep/2026:21:07:12 +0200] "GET /public/.git/config HTTP/1.1" 404 153 "-" "cru ...
show more
136.107.221.171 - - [04/Sep/2026:21:07:12 +0200] "GET /public/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:21:07:12 +0200] "GET /www/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:21:07:12 +0200] "GET /site/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:21:07:12 +0200] "GET /backend/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:21:07:12 +0200] "GET /src/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
...
show less
Hacking
Brute-Force
🇩🇪
FeG Deutschland
2026-09-04 18:06:13
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 16:42:26
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.221.171 (171.221.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.221.171 (171.221.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:42:22.107145 2026] [security2:error] [pid 28429:tid 28429] [client 136.107.221.171:50390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynosureservices.net"] [uri "/src/.git/config"] [unique_id "apr07vDTAR_Sf1aD8fxn9AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:36:25
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.221.171 (171.221.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.221.171 (171.221.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:36:17.410806 2026] [security2:error] [pid 19525:tid 19525] [client 136.107.221.171:53414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bluebirds.bickleton.org"] [uri "/app/.git/config"] [unique_id "aprJURENaLg1GflGDxNsJgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:55:45
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.221.171 (171.221.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.221.171 (171.221.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:55:40.167372 2026] [security2:error] [pid 19814:tid 19814] [client 136.107.221.171:46598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.abq4you.com"] [uri "/.git/config"] [unique_id "apqxvD77j-7sw5vlWAX11QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:54:08
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.221.171 (171.221.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.221.171 (171.221.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:54:03.534415 2026] [security2:error] [pid 2198739:tid 2198790] [client 136.107.221.171:57724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.backcountrygardens.com"] [uri "/.git/config"] [unique_id "appO64BVJpbByhLkkCCnXAAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-04 04:20:14
(17 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-04 04:17:19
(17 hours ago)
136.107.221.171 - - [04/Sep/2026:06:17:16 +0200] "GET /.git/config HTTP/1.1" 403 4443 "-" "crusader- ...
show more
136.107.221.171 - - [04/Sep/2026:06:17:16 +0200] "GET /.git/config HTTP/1.1" 403 4443 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:06:17:16 +0200] "GET /backend/.git/config HTTP/1.1" 404 4440 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:06:17:16 +0200] "GET /src/.git/config HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:06:17:16 +0200] "GET /app/.git/config HTTP/1.1" 404 4440 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:06:17:16 +0200] "GET /api/.git/config HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:06:17:16 +0200] "GET /html/.git/config HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:06:17:16 +0200] "GET /www/.git/config HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:06:17:16 +0200] "GET /public/.git/config HTTP/1.1" 404 4441 "-" "crusader-worker/1.0"
136.107.221.171 - - [04/Sep/2026:06:17:16 +0200] "GET /site/.git/con
show less
Web App Attack
Hacking
🇸🇪
vaia.cloud
2026-09-03 23:20:02
(22 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇨🇭
leo1305
2026-09-03 23:17:47
(22 hours ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-03 21:59:38
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-03
Web App Attack
SSH
Hacking
🇮🇹
CoreTech srl
2026-09-03 21:53:57
(1 day ago)
cloudlinux2 fail2ban: 2026-09-03 23:48:51,262 fail2ban.filter [1472]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-03 23:48:51,262 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.28.175.244 - 2026-09-03 23:48:51cloudlinux2 fail2ban: 2026-09-03 23:48:43,398 fail2ban.actions [1472]: NOTICE [plesk-modsecurity] Unban 34.84.4.66cloudlinux2 fail2ban: 2026-09-03 23:48:51,514 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.28.175.244 - 2026-09-03 23:48:51cloudlinux2 fail2ban: 2026-09-03 23:49:24,377 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 104.155.231.26 - 2026-09-03 23:49:24cloudlinux2 fail2ban: 2026-09-03 23:49:47,487 fail2ban.actions [1472]: NOTICE [plesk-modsecurity] Unban 8.228.15.105cloudlinux2 fail2ban: 2026-09-03 23:50:07,640 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 136.107.221.171 - 2026-09-03 23:50:07cloudlinux2 fail2ban: 2026-09-03 23:50:07,707 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 136.107.221.171 - 2026-09-03 23:50:07cloudlinux2 fail2ban: 2026-09-03 23:50
show less
Brute-Force
🇩🇪
raph
2026-09-03 19:54:38
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack