๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:03:34
(4 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐จ๐ญ
TheCoon
2026-06-09 21:15:02
(5 hours ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ณ๐ฑ
thedreamer.nl
2026-06-09 14:02:19
(12 hours ago)
136.107.90.96 - - [09/Jun/2026:15:56:49 +0200] "GET /.git/ HTTP/1.1" 403 146 "-" "Mozilla/5.0 (Windo ...
show more
136.107.90.96 - - [09/Jun/2026:15:56:49 +0200] "GET /.git/ HTTP/1.1" 403 146 "-" "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "US" "Washington" "38.89400" "-77.03650"
136.107.90.96 - - [09/Jun/2026:15:56:49 +0200] "GET /.git/hooks/post-commit.sample HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "US" "Washington" "38.89400" "-77.03650"
136.107.90.96 - - [09/Jun/2026:15:56:49 +0200] "GET /.git/COMMIT_EDITMSG HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "US" "Washington" "38.89400" "-77.03650"
136.107.90.96 - - [09/Jun/2026:15:56:49 +0200] "GET /.git/hooks/post-receive.sample HTTP/1.1" 404 146 "-" "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "US" "Washington" "38.89400" "-77.03650"
...
show less
Brute-Force
Bad Web Bot
๐ฆ๐บ
2000cn.com.au
2026-06-09 13:51:02
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 13:20:41
(13 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.107.90.96 (96.90.107.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 136.107.90.96 (96.90.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:20:36.191210 2026] [security2:error] [pid 7598:tid 7598] [client 136.107.90.96:36746] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "tikehaubookings.com"] [uri "/.git/config"] [unique_id "aigTJLdkxrKvxGWDXgqA7wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:20:07
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.90.96 (96.90.107.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.90.96 (96.90.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:20:00.962190 2026] [security2:error] [pid 3997:tid 3997] [client 136.107.90.96:34894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gonzalezmultiservicios.com"] [uri "/.git/config"] [unique_id "aigE8EWqSiJHhRGxJUyJ3AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:00:52
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.90.96 (96.90.107.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.90.96 (96.90.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:00:44.962207 2026] [security2:error] [pid 26291:tid 26291] [client 136.107.90.96:44276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mohsep-eg.com"] [uri "/.git/config"] [unique_id "aigAbEzYn7HYt2nahAba_AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mashamal
2026-06-09 11:51:16
(14 hours ago)
Vulnerability Probe
...
Web App Attack
๐จ๐ฆ
1gz
2026-06-09 10:56:32
(15 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: CHALLENGE
Protocol: HTTP/1.1 (GET m ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 09:03:00
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.90.96 (96.90.107.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.90.96 (96.90.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:02:57.118344 2026] [security2:error] [pid 30200:tid 30200] [client 136.107.90.96:53158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inetbrain.com"] [uri "/.git/config"] [unique_id "aifWwZtKxYEjUgygrVix8wAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 08:58:08
(17 hours ago)
136.107.90.96 - - [09/Jun/2026:08:58:06 +0000] "GET /.git/config HTTP/1.1" 404 44323 "-" "Mozilla/5. ...
show more
136.107.90.96 - - [09/Jun/2026:08:58:06 +0000] "GET /.git/config HTTP/1.1" 404 44323 "-" "Mozilla/5.0 (Linux; Android 8.0.0; d-02K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.105 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 07:51:05
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.90.96 (96.90.107.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.90.96 (96.90.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:51:01.790556 2026] [security2:error] [pid 20067:tid 20067] [client 136.107.90.96:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.forsaleincr.com"] [uri "/.git/config"] [unique_id "aifF5T0Ow6cIOguIrXD8HAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
McClay
2026-06-09 07:39:52
(19 hours ago)
Illegal access attempt:136.107.90.96 - - [09/Jun/2026:09:39:52 +0200] "GET /.git/config HTTP/1.1" 40 ...
show more
Illegal access attempt:136.107.90.96 - - [09/Jun/2026:09:39:52 +0200] "GET /.git/config HTTP/1.1" 404 3619 "-" "w3m/0.5.1"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
iNetWorker
2026-06-09 06:57:17
(19 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐จ๐ญ
4server
2026-06-09 06:51:46
(19 hours ago)
[TueJun0908:51:42.2148802026][security2:error][pid4050314:tid4050347][client136.107.90.96:0]ModSecur ...
show more
[TueJun0908:51:42.2148802026][security2:error][pid4050314:tid4050347][client136.107.90.96:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webdisk.eutecne.ch\"][uri\"/.git/config\"][unique_id\"aie3_r1UYP1JFGq4FUzh6AAAAUc\"]
show less
Hacking
Web App Attack