🇧🇪
webbie
2026-09-05 10:41:34
(5 hours ago)
136.110.68.0 - - [05/Sep/2026:12:41:33 +0200] "GET /.git/config HTTP/1.1" 404 5220 "-" "crusader-wor ...
show more
136.110.68.0 - - [05/Sep/2026:12:41:33 +0200] "GET /.git/config HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
136.110.68.0 - - [05/Sep/2026:12:41:33 +0200] "GET /app/.git/config HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
136.110.68.0 - - [05/Sep/2026:12:41:33 +0200] "GET /src/.git/config HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
136.110.68.0 - - [05/Sep/2026:12:41:33 +0200] "GET /api/.git/config HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
136.110.68.0 - - [05/Sep/2026:12:41:33 +0200] "GET /www/.git/config HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-04 22:59:40
(17 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wordpress/.git/config (+11 more) | 2026-09-04 22:59 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:50:46
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.68.0 (0.68.110.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.68.0 (0.68.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:50:41.722245 2026] [security2:error] [pid 22483:tid 22483] [client 136.110.68.0:35228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.doubloonswap.com"] [uri "/backend/.git/config"] [unique_id "aps9McAmp8MyZ_nC3vmRkwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 21:19:00
(18 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 21:02:25
(18 hours ago)
Multiple WAF Violations
Web App Attack
🇮🇳
Starburst SysOp Team
2026-09-04 20:27:31
(19 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-bom2-2)
Hacking
Web App Attack
🇨🇭
Ribeye375
2026-09-04 17:17:25
(22 hours ago)
HIPS nginx-access-errors - Block tcp/http,https
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 16:14:49
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.68.0 (0.68.110.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.68.0 (0.68.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:14:46.737851 2026] [security2:error] [pid 3195503:tid 3195592] [client 136.110.68.0:55626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nicholsinvest.com"] [uri "/src/.git/config"] [unique_id "aprudkj7yHX7KVVl_0hXqAAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-09-04 16:00:14
(23 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 11:51:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.68.0 (0.68.110.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.68.0 (0.68.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:51:51.265593 2026] [security2:error] [pid 29515:tid 29515] [client 136.110.68.0:40880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wall.cswiki.us"] [uri "/src/.git/config"] [unique_id "apqw13nYr89YfA7NmItpawAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 11:35:03
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:23:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.68.0 (0.68.110.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.68.0 (0.68.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:23:51.973061 2026] [security2:error] [pid 4065:tid 4065] [client 136.110.68.0:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atlascoombs.com"] [uri "/backend/.git/config"] [unique_id "apqcN81rM06-MxV3SDnTnAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 04:59:55
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking